CVE-2024-23743: Notion
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."
Affected products
- Notion Notion: up to and including 3.1.0
Published 2024-01-28. Last modified 2026-06-17.