CVE-2020-16608: Notable

Critical severity, CVSS 9.6. EPSS: 4.5% chance of exploitation in the next 30 days.

Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

Affected products

  • Notable Notable: version 1.8.4 only

Published 2020-12-10. Last modified 2026-06-17.