CVE-2026-17497
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
| CWE | CWE-78 CWE-1249 CWE-276 |
| Vendor | codexu |
| Product | notegen |
| Published | Jul 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for codexu notegen
Be the first to know when new high vulnerabilities affecting codexu notegen are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
codexu / NoteGen
0 < 0.32.0
References
Credits
Yuval Moravchick JFrog Security Research