๐Ÿ” CVE Alert

CVE-2026-17497

HIGH 8.3

NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.

CWE CWE-78 CWE-1249 CWE-276
Vendor codexu
Product notegen
Published Jul 26, 2026
Stay Ahead of the Next One

Get instant alerts for codexu notegen

Be the first to know when new high vulnerabilities affecting codexu notegen are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

codexu / NoteGen
0 < 0.32.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/codexu/note-gen/commit/00064a4a8ec4177d51094ffb3e15bf0758009c1f github.com: https://github.com/codexu/note-gen/releases/tag/note-gen-v0.32.0 github.com: https://github.com/codexu/note-gen

Credits

Yuval Moravchick JFrog Security Research