Stored XSS Vulnerability in Notesnook Note-Taking App
CVE-2026-33978
5.4MEDIUM
What is CVE-2026-33978?
A stored XSS vulnerability exists in the Notesnook note-taking app prior to version 3.3.17. This flaw allows attackers to manipulate clip metadata that is subsequently rendered as HTML without proper escaping. By controlling shared title metadata via mobile share or link-preview data, an attacker can inject malicious HTML elements. When a victim engages with the Notesnook share flow and selects the web clip option, the payload is executed within the mobile editor WebView, potentially compromising user security. A patch addressing this vulnerability can be found in version 3.3.17.
Affected Version(s)
notesnook < 3.3.17
