CVE-2026-17497
HIGHNoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
Title source: cnaDescription
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
References (3)
Core 3
Core References
Patch patch
Fix: remove unrestricted shell execute for bash/python; harden skill script execution
https://github.com/codexu/note-gen/commit/00064a4a8ec4177d51094ffb3e15bf0758009c1f
Vendor Advisory vendor-advisory
NoteGen v0.32.0 release
https://github.com/codexu/note-gen/releases/tag/note-gen-v0.32.0
Scores
CVSS v3
8.3
EPSS
0.0046
EPSS Percentile
37.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-1249
CWE-276
CWE-78
Status
published
Products (1)
codexu/NoteGen
< 0.32.0
Published
Jul 26, 2026
Tracked Since
Jul 26, 2026