cvefeed high severity News Jul 26, 2026 CVE-2026-17497 - NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python A remote code execution vulnerability in NoteGen before version 0.32.0 caused by overly permissive Tauri shell plugin execute capabilities, allowing webview JavaScript to run attacker-controlled OS commands. Read more