CVE-2019-17051: Evernote
High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.
Affected products
- Evernote Evernote: before 7.13 (fixed in 7.13)
Published 2019-09-30. Last modified 2026-06-17.