CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-17497

highCVSS 8.3covered by 1 sourcefirst seen 2026-07-26
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.

⚡ Watch CVE-2026-17497

Get an email if CVE-2026-17497 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-17497

CVE.org record

Embed the live status

CVE-2026-17497 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-17497 status](https://www.csirts.com/badge/CVE-2026-17497)](https://www.csirts.com/cve/CVE-2026-17497)