CVE Feed

    Dashboard / CVE / CVE-2026-17496

    CVE-2026-17496

    NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).

    Published:Jul 26, 2026
    Last Modified:Aug 25, 2026
    EPS:Jul 26, 2026
    EPSS Score:0.00318
    CVSS Score:8.1

    Affected Products

    Vendor
    Codexu
    Product
    Notegen
    Vendor
    Notegen
    Product
    Notegen

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High