CVE-2020-16608

Published
View on NVD ↗
CVSS v3
9.6
CRITICAL
CVSS v2
9.3
HIGH
Affected
1
PROJECT

Description

Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

The Markdown-based note-taking app that doesn't suck.
GitHubGitHub
23.5K