Critical Remote Code Execution Vulnerability in NoteGen (CVE-2026-17497)

Critical Remote Code Execution Vulnerability in NoteGen (CVE-2026-17497)

First seen 27 Jul 2026, 10:33 UTC Mallory.Aicvefeed.ionvd.nist.govcwe.mitre.orgwww.cve.org 93% similarity 70.5

Article Content

Browse articles
ThreatCluster

CVE-2026-17497 is a high-severity remote code execution vulnerability affecting NoteGen versions prior to 0.32.0. The flaw arises from an overly permissive Tauri shell plugin configuration that allows JavaScript in the application's webview to execute arbitrary OS commands. This can lead to full remote code execution on the user's machine if an attacker can execute scripts in the webview, such as through cross-site scripting. No public exploits have been reported yet, but the vulnerability poses a significant risk to users of affected versions. Organizations are advised to patch their systems promptly to mitigate potential exploitation. The vulnerability was published on July 26, 2026.

Key Points: • CVE-2026-17497 allows remote code execution via the Tauri shell plugin in NoteGen. • Affected versions are those prior to 0.32.0, with no public exploits currently observed. • Immediate patching is recommended to prevent potential exploitation.

ThreatCluster AI

Timeline

2026-07-26
CVE-2026-17497 published
A remote code execution vulnerability in NoteGen was disclosed, affecting versions before 0.32.0.
cvefeed.io
2026-07-27
Vulnerability reported by multiple sources
Both cvefeed.io and Mallory.Ai reported on the critical nature of CVE-2026-17497 and its implications.
Mallory.Ai

Community

Browse all →

Tracked Entities in This Story