CVE-2020-35717: Electronjs Zonote
Critical severity, CVSS 9.0. EPSS: 3.8% chance of exploitation in the next 30 days.
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
Affected products
- Electronjs Zonote: up to and including 0.4.0
Published 2021-01-01. Last modified 2026-06-17.