Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.3
CVE-2026-17497
- EPSS 0.46%
- Veröffentlicht 26.07.2026 14:38:08
- Zuletzt bearbeitet 25.08.2026 15:30:35
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:s...
8.1
CVE-2026-17496
- EPSS 0.3%
- Veröffentlicht 26.07.2026 14:33:02
- Zuletzt bearbeitet 25.08.2026 15:30:20
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled conten...
1