8.3highHigh

CVE-2026-17497

Notegen Notegen

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, no account is needed.
  • Beyond that, someone has to be persuaded to take an action first.

Scoring

CVSS
8.3 (v3.1)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness
CWE-78
Assigned by
reefs@jfrog.com

Dates

Published
2026-07-26
Last modified
2026-08-25
Sources
NVD

Affected products

  • Notegen Notegen- 0.32.0

As listed in the NVD configuration data. Not a statement about your estate.

References