CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-17496

highCVSS 8.1covered by 1 sourcefirst seen 2026-07-26
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).

⚡ Watch CVE-2026-17496

Get an email if CVE-2026-17496 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-17496

CVE.org record

Embed the live status

CVE-2026-17496 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-17496 status](https://www.csirts.com/badge/CVE-2026-17496)](https://www.csirts.com/cve/CVE-2026-17496)