CVE-2024-23743: Notion

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."

Affected products

  • Notion Notion: up to and including 3.1.0

Published 2024-01-28. Last modified 2026-06-17.