CVE-2023-50643

CRITICAL

Evernote for macOS 10.68.2 - Remote Code Execution via RunAsNode and enableNodeClilnspectArguments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-50643. PoCs published by giovannipajeu1.

AI-analyzed exploit summary The repository provides a technical writeup for CVE-2023-50643, detailing an arbitrary code execution vulnerability in Evernote for macOS v10.68.2 via the RunAsNode and enableNodeClilnspectArguments components. It includes screenshots of the exploitation process using the electroniz3r tool but lacks functional exploit code.

Description

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

Exploits (2)

nomisec WRITEUP 8 stars
by giovannipajeu1 · poc
https://github.com/giovannipajeu1/CVE-2023-50643

The repository provides a technical writeup for CVE-2023-50643, detailing an arbitrary code execution vulnerability in Evernote for macOS v10.68.2 via the RunAsNode and enableNodeClilnspectArguments components. It includes screenshots of the exploitation process using the electroniz3r tool but lacks functional exploit code.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Evernote for macOS v10.68.2
No auth needed
Prerequisites: Access to the target system · Evernote for macOS v10.68.2 installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
inthewild WRITEUP
poc
https://github.com/v3x0r/cve-2023-50643

The repository provides a technical writeup for CVE-2023-50643, detailing an arbitrary code execution vulnerability in Evernote for macOS v10.68.2 via the RunAsNode and enableNodeClilnspectArguments components. It includes screenshots of the exploitation process using the electroniz3r tool but lacks functional exploit code.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Evernote for macOS v10.68.2
No auth needed
Prerequisites: electroniz3r tool · access to vulnerable Evernote instance
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.2693
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

Status published
Products (1)
evernote/evernote 10.68.2
Published Jan 09, 2024
Tracked Since Feb 18, 2026