CVE-2026-33976 is a critical stored Cross-Site Scripting (XSS) vulnerability in the Notesnook note-taking application's Web Clipper, affecting Web/Desktop versions prior to 3.3.11 and Android/iOS prior to 3.3.17. This flaw allows an attacker to embed malicious code from a clipped webpage, which, when opened, executes within an unsandboxed iframe, leading to Remote Code Execution (RCE) in the desktop application due to insecure Electron configurations. Rated 9.6 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), it requires user interaction but can result in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code available, the vulnerability has garnered community discussion, emphasizing the importance of applying the provided patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.11CPE matchmatch criteria | cpe:2.3:a:streetwriters:notesnook_desktop:*:*:*:*:*:*:*:* | ||
< 3.3.17CPE matchmatch criteria | cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:android:*:* | ||
< 3.3.17CPE matchmatch criteria | cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.