CVE-2026-31876
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/03/2026
Last modified:
17/03/2026
Description
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an HTML string without escaping, which was then assigned to the srcdoc attribute of an . This vulnerability is fixed in 3.3.9.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:streetwriters:notesnook_desktop:*:*:*:*:*:*:*:* | 3.3.9 (excluding) | |
| cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:android:*:* | 3.3.15 (excluding) | |
| cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:iphone_os:*:* | 3.3.15 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



