Cross-Site Scripting Vulnerability in sheshbabu zen Note Editor
CVE-2026-97868
Key Information:
Badges
What is CVE-2026-97868?
A vulnerability has been identified in the Note Editor component of the sheshbabu zen product, specifically related to the use of the dangerouslySetInnerHTML function in NotesEditor.jsx. This issue allows an attacker to inject malicious scripts into a web page, leading to cross-site scripting (XSS). The attack can be executed remotely, posing a significant risk to users who utilize this feature to edit or display notes. The vendor was approached regarding this vulnerability but did not provide a response, leaving users potentially exposed to exploitation.
Affected Version(s)
zen 1.0
zen 1.1
zen 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
