What is CVE-2026-17497?
CVE-2026-17497: NoteGen versions before 0.32.0 grant the Tauri shell plugin 'shell:allow-execute' permission for bash, python, and python3 with arbitrary arguments in default desktop capabilities. This allows JavaScript running in the webview to execute attacker-controlled operating system commands via 'plugin:shell|execute'. Affected users should immediately upgrade to NoteGen version 0.32.0 or later.
Azərbaycanca: CVE-2026-17497: NoteGen-in 0.32.0-dən əvvəlki versiyalarında Tauri shell plaqininin default konfiqurasiyası bash, python və python3 üçün "shell:allow-execute" icazəsi verir. Bu, veb-səhifədə işləyən JavaScript koduna "plugin:shell|execute" vasitəsilə əməliyyat sistemində ixtiyari əmrlər icra etməyə imkan yaradır. Təsirlənən istifadəçilər dərhal NoteGen-i 0.32.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which NoteGen users are affected by CVE-2026-17497?
Users running NoteGen versions before 0.32.0 are affected.
What should users do to protect against CVE-2026-17497?
Users should immediately upgrade to NoteGen version 0.32.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.