CVE-2026-42090Disclosure(streetwriters / notesnook_desktop)

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch streetwriters notesnook_desktop systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML template without HTML escaping. When the note is later exported to PDF, Notesnook renders that HTML into a same-origin, unsandboxed iframe using iframe.srcdoc = .... Injected script executes in the Notesnook origin. In the desktop app, this becomes RCE because Electron is configured with nodeIntegration: true and contextIsolation: false. This issue has been patched in Notesnook Web/Desktop version 3.3.15 and Notesnook iOS/Android version 3.3.20.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notesnook_desktop
  • notesnook_mobile

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-04); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Products
notesnook_desktopnotesnook_mobile

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-04: 3Mentions · 2026-05-13: 2Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-13: 105-0405-13
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-043
Disclosure1General1Patch1
2026-05-132
Disclosure1General1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42090-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text provides a link to a research advisory for CVE‑2026‑42090 but contains no explicit information on PoCs, exploits, active use, patches, technical details, or debunking, leading to a low confidence general classification.

    0001030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42090 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post merely lists CVE‑2026‑42090 with its CVSS score and a critical severity rating, without providing further exploitation or patch details.

    1000038
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42090 Stored XSS Escalation to Remote Code Execution in Notesnook Desktop Prior to 3.3.15 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42090

    Post summary

    The provided text merely cites CVE‑2026‑42090 with a headline and link, offering no actionable details on PoC, exploit code, or mitigation.

    0000046
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42090 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20,… https://www.cve.org/CVERecord?id=CVE-2026-42090 ----- Traducción: CVE-2026-42090 Not… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-42090, noting affected Notesnook versions and linking to the official CVE record, but provides no further details.

    0000041
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-42090 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20,… https://www.cve.org/CVERecord?id=CVE-2026-42090

    Post summary

    The note outlines that CVE-2026-42090 affects Notesnook versions prior to 3.3.15/Web/Desktop and 3.3.20/Android, with newer releases containing a fix.

    00000151
    57.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appstreetwritersnotesnook_desktop---
Appstreetwritersnotesnook_mobile-android-
Appstreetwritersnotesnook_mobile-iphone_os-

Explore more