Remote Code Execution Vulnerability in NoteGen by Codexu
CVE-2026-17497
8.3HIGH
What is CVE-2026-17497?
The vulnerability in NoteGen before version 0.32.0 permits the execution of arbitrary operating system commands due to improper handling of the Tauri shell plugin. This can lead to a critical security risk where JavaScript running in the application webview can trigger the command execution functionality, potentially allowing attackers to execute malicious scripts or commands with the same privileges as the NoteGen process. When exploited, especially in conjunction with cross-site scripting (XSS) attacks, this vulnerability enables attackers to gain full control over user systems.
Affected Version(s)
NoteGen 0 < 0.32.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Yuval Moravchick
JFrog Security Research
