Stored XSS Vulnerability in Notesnook Note-Taking App
CVE-2026-33978

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-33978?

A stored XSS vulnerability exists in the Notesnook note-taking app prior to version 3.3.17. This flaw allows attackers to manipulate clip metadata that is subsequently rendered as HTML without proper escaping. By controlling shared title metadata via mobile share or link-preview data, an attacker can inject malicious HTML elements. When a victim engages with the Notesnook share flow and selects the web clip option, the payload is executed within the mobile editor WebView, potentially compromising user security. A patch addressing this vulnerability can be found in version 3.3.17.

Affected Version(s)

notesnook < 3.3.17

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.