Remote Code Execution Vulnerability in NoteGen by Codexu
CVE-2026-17497

8.3HIGH

Key Information:

Vendor

Codexu

Status
Vendor
CVE Published:
26 July 2026

Badges

👾 Exploit Exists

What is CVE-2026-17497?

The vulnerability in NoteGen before version 0.32.0 permits the execution of arbitrary operating system commands due to improper handling of the Tauri shell plugin. This can lead to a critical security risk where JavaScript running in the application webview can trigger the command execution functionality, potentially allowing attackers to execute malicious scripts or commands with the same privileges as the NoteGen process. When exploited, especially in conjunction with cross-site scripting (XSS) attacks, this vulnerability enables attackers to gain full control over user systems.

Affected Version(s)

NoteGen 0 < 0.32.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Moravchick
JFrog Security Research
.