LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33955

CVE-2026-33955 - Vulnerability Analysis

HighCVSS: 8.6

Last Updated: March 27, 2026

Notesnook - Stored XSS & Remote Code Execution

Published: March 27, 2026Updated: March 27, 2026

Overview

Notesnook Web/Desktop < 3.3.11 contains a stored cross-site scripting caused by insecure use of dangerouslySetInnerHTML in note history comparison viewer, letting attackers escalate to remote code execution in desktop app, exploit requires crafted note header and backup/restore feature.

Severity & Score

Severity: High
CVSS Score: 8.6
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute remote code on the desktop application, potentially taking full control of the user's system.

Mitigation

Update to version 3.3.11 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

🟠 CVE-2026-33955 - High (8.6) Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when a... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33955/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

🟠 CVE-2026-33955 - High (8.6) Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when a... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33955/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-33955
Severity
High
CVSS Score
8.6
Type
stored_xss
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days