CVE-2024-23743

LOW

Notion <3.1.0 - RCE

Title source: llm

Description

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."

Exploits (2)

nomisec WRITEUP 1 stars
by giovannipajeu1 · poc
https://github.com/giovannipajeu1/CVE-2024-23743
inthewild WRITEUP
poc
https://github.com/v3x0r/cve-2024-23743

Scores

CVSS v3 3.3
EPSS 0.0016
EPSS Percentile 36.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-250
Status published
Products (1)
notion/notion < 3.1.0
Published Jan 28, 2024
Tracked Since Feb 18, 2026