CVE-2026-17497

Source
https://cve.org/CVERecord?id=CVE-2026-17497
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17497.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17497
Published
2026-07-26T14:38:08.960Z
Modified
2026-07-27T04:02:31.211182881Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
Details

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17497.json",
    "cwe_ids": [
        "CWE-1249",
        "CWE-276",
        "CWE-78"
    ],
    "cna_assigner": "JFROG"
}
References

Affected packages

Git / github.com/codexu/note-gen

Affected ranges

Type
GIT
Repo
git://github.com/codexu/note-gen
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
8a40efd90a9089dfaa6cacdd245504cce821b1d8
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.32.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

app-v0.*
app-v0.10.0
app-v0.10.1
app-v0.10.2
app-v0.10.3
app-v0.10.4
app-v0.10.5
app-v0.10.6
app-v0.10.7
app-v0.10.8
app-v0.11.0
app-v0.12.0
app-v0.12.1
app-v0.12.2
app-v0.12.3
app-v0.12.4
app-v0.13.0
app-v0.13.1
app-v0.13.2
app-v0.13.3
app-v0.13.4
app-v0.13.5
app-v0.13.6
app-v0.13.7
app-v0.14.0
app-v0.15.0
app-v0.16.0
app-v0.16.1
app-v0.2.0
app-v0.2.1
app-v0.3.0
app-v0.4.0
app-v0.4.1
app-v0.4.2
app-v0.4.3
app-v0.4.4
app-v0.5.0
app-v0.5.1
app-v0.5.10
app-v0.5.11
app-v0.5.17
app-v0.5.18
app-v0.5.19
app-v0.5.2
app-v0.5.20
app-v0.5.3
app-v0.5.4
app-v0.5.5
app-v0.5.6
app-v0.5.7
app-v0.5.8
app-v0.5.9
app-v0.6.0
app-v0.6.1
app-v0.6.2
app-v0.6.3
app-v0.6.4
app-v0.7.0
app-v0.7.1
app-v0.7.2
app-v0.7.3
app-v0.7.4
app-v0.7.5
app-v0.7.6
app-v0.7.7
app-v0.7.8
app-v0.7.9
app-v0.8.0
app-v0.8.1
app-v0.8.2
app-v0.8.3
app-v0.9.0
app-v0.9.1
note-gen-v0.*
note-gen-v0.16.2
note-gen-v0.16.3
note-gen-v0.16.4
note-gen-v0.16.5
note-gen-v0.17.0
note-gen-v0.17.1
note-gen-v0.17.2
note-gen-v0.17.3
note-gen-v0.19.10
note-gen-v0.19.11
note-gen-v0.19.3
note-gen-v0.19.4
note-gen-v0.19.5
note-gen-v0.19.6
note-gen-v0.19.7
note-gen-v0.19.8
note-gen-v0.19.9
note-gen-v0.20.0
note-gen-v0.20.1
note-gen-v0.20.2
note-gen-v0.20.3
note-gen-v0.21.0
note-gen-v0.21.1
note-gen-v0.21.2
note-gen-v0.21.3
note-gen-v0.22.0
note-gen-v0.22.1
note-gen-v0.22.2
note-gen-v0.22.3
note-gen-v0.22.4
note-gen-v0.23.0
note-gen-v0.23.1
note-gen-v0.23.2
note-gen-v0.23.3
note-gen-v0.23.4
note-gen-v0.23.5
note-gen-v0.23.6
note-gen-v0.23.7
note-gen-v0.24.0
note-gen-v0.24.1
note-gen-v0.25.0
note-gen-v0.25.1
note-gen-v0.25.2
note-gen-v0.25.3
note-gen-v0.25.4
note-gen-v0.26.0
note-gen-v0.26.1
note-gen-v0.26.2
note-gen-v0.26.3
note-gen-v0.26.4
note-gen-v0.26.5
note-gen-v0.27.0
note-gen-v0.27.1
note-gen-v0.27.2
note-gen-v0.27.3
note-gen-v0.27.4
note-gen-v0.27.5
note-gen-v0.27.6
note-gen-v0.27.7
note-gen-v0.27.8
note-gen-v0.27.9
note-gen-v0.28.0
note-gen-v0.29.0
note-gen-v0.29.1
note-gen-v0.29.2
note-gen-v0.30.0
note-gen-v0.30.1
note-gen-v0.31.0
note-gen-v0.31.1
note-gen-v0.31.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17497.json"