Sploitus

CVE-2026-31876

No indexed exploits for CVE-2026-31876 yet

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an HTML string without escaping, which was then assigned to the srcdoc attribute of an <iframe>. This vulnerability is fixed in 3.3.9.

Streetwriters Notesnook Desktop
< 3.3.9
Streetwriters Notesnook Mobile
< 3.3.15
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (7th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2026-03-11
CVE-2026-31876 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-31876 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-31876 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.