{"id":7602,"date":"2026-04-21T20:31:31","date_gmt":"2026-04-21T18:31:31","guid":{"rendered":"https:\/\/yoota.it\/en\/notesnook-patches-another-desktop-security-flaw-update-now\/"},"modified":"2026-04-21T20:31:33","modified_gmt":"2026-04-21T18:31:33","slug":"notesnook-patches-another-desktop-security-flaw-update-now","status":"publish","type":"post","link":"https:\/\/yoota.it\/en\/notesnook-patches-another-desktop-security-flaw-update-now\/","title":{"rendered":"Notesnook patches another desktop security flaw: update now"},"content":{"rendered":"\n<p>Notesnook, the end-to-end encrypted note-taking app, has been patching security issues at a faster pace than usual over the past few weeks. The latest fix arrived in desktop version 3.3.15, released April 20, addressing a vulnerability that could allow remote code execution through malicious scripts hidden in note content.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The PDF export problem<\/h3>\n\n\n\n<p>The vulnerability exploited the PDF export function: specially crafted content could trigger a <a target=\"_blank\" href=\"https:\/\/owasp.org\/www-community\/attacks\/xss\/\" rel=\"noopener\">persistent XSS<\/a> during rendering, which in the Electron-based desktop app translates to arbitrary command execution on the user&#8217;s system. Security researcher <a target=\"_blank\" href=\"https:\/\/github.com\/iiihaiii\" rel=\"noopener\">iiihaiii<\/a> reported the issue responsibly, and the team confirmed no user action beyond updating is needed.<\/p>\n\n\n\n<p>This marks the third security issue patched in Notesnook within weeks. Previous fixes included an XSS in the note history viewer (CVE-2026-33955, patched in 3.3.11) and another in the mobile sharing feature (CVE-2026-33976, fixed in 3.3.17 for Android and iOS). All three flaws share the same root cause: user-controlled content rendered without proper sanitization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What else is in 3.3.15<\/h3>\n\n\n\n<p>The update adds the ability to empty the trash directly from the context menu in the sidebar, right-click on trash and you&#8217;re done. Among the bug fixes, the most annoying one addressed a Windows issue where the app would occasionally uninstall itself during updates. Also resolved was a dark mode display problem with the PDF search box becoming unreadable.<\/p>\n\n\n\n<p>If you&#8217;re running Notesnook on desktop, update as soon as possible.<\/p>\n\n\n\n    \n    <div class=\"yoota-fonte\">\n        <a href=\"https:\/\/blog.notesnook.com\/notesnook-desktop-v3.3.15\" target=\"_blank\" rel=\"nofollow noopener\" class=\"yoota-fonte-hit\">\n            \n            <span class=\"yoota-fonte-icon\" aria-hidden=\"true\">\n                <i class=\"ri-external-link-line\"><\/i>\n            <\/span>\n\n            <span class=\"yoota-fonte-content\">\n                <span class=\"yoota-fonte-label\">SOURCE:\/\/<\/span>\n\n                                    <span class=\"yoota-fonte-link\">\n                        blog.notesnook.com                    <\/span>\n                            <\/span>\n\n        <\/a>\n    <\/div>\n    \n    \n\n\n\n    \n    <div class=\"yoota-fonte\">\n        <a href=\"https:\/\/www.thehackerwire.com\/notesnook-stored-xss-escalates-to-rce-cve-2026-33976\/\" target=\"_blank\" rel=\"nofollow noopener\" class=\"yoota-fonte-hit\">\n            \n            <span class=\"yoota-fonte-icon\" aria-hidden=\"true\">\n                <i class=\"ri-external-link-line\"><\/i>\n            <\/span>\n\n            <span class=\"yoota-fonte-content\">\n                <span class=\"yoota-fonte-label\">SOURCE:\/\/<\/span>\n\n                                    <span class=\"yoota-fonte-link\">\n                        thehackerwire.com                    <\/span>\n                            <\/span>\n\n        <\/a>\n    <\/div>\n    \n    \n\n\n\n    \n    <div class=\"yoota-fonte\">\n        <a href=\"https:\/\/www.thehackerwire.com\/notesnook-rce-via-stored-xss-in-history-viewer\/\" target=\"_blank\" rel=\"nofollow noopener\" class=\"yoota-fonte-hit\">\n            \n            <span class=\"yoota-fonte-icon\" aria-hidden=\"true\">\n                <i class=\"ri-external-link-line\"><\/i>\n            <\/span>\n\n            <span class=\"yoota-fonte-content\">\n                <span class=\"yoota-fonte-label\">SOURCE:\/\/<\/span>\n\n                                    <span class=\"yoota-fonte-link\">\n                        thehackerwire.com                    <\/span>\n                            <\/span>\n\n        <\/a>\n    <\/div>\n    \n    \n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Notesnook 3.3.15 for desktop patches a vulnerability that could enable arbitrary code execution via PDF export. This is the third security fix rolled out by the app in recent weeks.<\/p>\n","protected":false},"author":2,"featured_media":7601,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"italian_url":"https:\/\/yoota.it\/notesnook-risolve-unaltra-vulnerabilita-nel-desktop-e-importante-aggiornare\/","yoota_meta_description":"","activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":4,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"federated","footnotes":""},"categories":[21],"tags":[643,271,272],"class_list":["post-7602","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-messaging","tag-electron","tag-notesnook","tag-security"],"_links":{"self":[{"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/posts\/7602","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/comments?post=7602"}],"version-history":[{"count":1,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/posts\/7602\/revisions"}],"predecessor-version":[{"id":7604,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/posts\/7602\/revisions\/7604"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/media\/7601"}],"wp:attachment":[{"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/media?parent=7602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/categories?post=7602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yoota.it\/en\/wp-json\/wp\/v2\/tags?post=7602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}