CVE-2024-0849: Leanote Desktop

Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.

Affected products

  • Leanote Desktop: version 2.7.0 only

Published 2024-02-07. Last modified 2026-06-17.