CVE-2026-17496
HIGHNoteGen chat preview XSS via unsanitized AI/skill HTML rendering
Title source: cnaDescription
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).
References (3)
Core 3
Core References
Patch patch
Fix: chat rendering moved to Streamdown
https://github.com/codexu/note-gen/commit/ae3ba948c41d8a74b4a20f4c6f26fcdda2002298
Vendor Advisory vendor-advisory
NoteGen v0.32.0 release
https://github.com/codexu/note-gen/releases/tag/note-gen-v0.32.0
Scores
CVSS v3
8.1
EPSS
0.0030
EPSS Percentile
22.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (1)
codexu/NoteGen
< 0.32.0
Published
Jul 26, 2026
Tracked Since
Jul 26, 2026