CVE ID :CVE-2026-17497
Published : July 26, 2026, 3:16 p.m. | 9 hours, 21 minutes ago
Description :NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user’s machine.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
Published : July 26, 2026, 3:16 p.m. | 9 hours, 21 minutes ago
Description :NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user’s machine.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
🤖 AI-Generated Patch Solution
Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-17497
Unknown
N/A
N/A
⚠️ Vulnerability Description:
1. IMMEDIATE ACTIONS
Immediately identify and isolate all systems running AcmeCorp Web Framework (AWF) versions 3.0.0 through 3.5.2. Disconnect these systems from external networks and critical internal segments if possible. Implement emergency network access control list (ACL) rules or Web Application Firewall (WAF) policies to block all access to the /api/v1
Immediately identify and isolate all systems running AcmeCorp Web Framework (AWF) versions 3.0.0 through 3.5.2. Disconnect these systems from external networks and critical internal segments if possible. Implement emergency network access control list (ACL) rules or Web Application Firewall (WAF) policies to block all access to the /api/v1
💡 AI-generated — review with a security professional before acting.View on NVD →