Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:iphone_os:*:* |
Mon, 16 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Streetwriters notesnook Desktop
Streetwriters notesnook Mobile |
|
| CPEs | cpe:2.3:a:streetwriters:notesnook_desktop:*:*:*:*:*:*:*:* cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:android:*:* cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:ios:*:* |
|
| Vendors & Products |
Streetwriters notesnook Desktop
Streetwriters notesnook Mobile |
Thu, 12 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Streetwriters
Streetwriters notesnook |
|
| Vendors & Products |
Streetwriters
Streetwriters notesnook |
Wed, 11 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an HTML string without escaping, which was then assigned to the srcdoc attribute of an <iframe>. This vulnerability is fixed in 3.3.9. | |
| Title | Notesnook has Stored XSS via unsanitized Twitter/X embed URL in editor (`tweetToEmbed`) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-12T20:08:12.048Z
Reserved: 2026-03-09T19:02:25.014Z
Link: CVE-2026-31876
Updated: 2026-03-12T20:08:09.400Z
Status : Analyzed
Published: 2026-03-11T19:16:04.140
Modified: 2026-03-17T15:59:17.190
Link: CVE-2026-31876
No data.
OpenCVE Enrichment
Updated: 2026-03-20T15:29:57Z