Loading
Generated remediation guidance and an executive summary. No account required.
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
Cite this page
CVE-2020-35717. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2020-35717
Use CWE-79, Electronjs vendor hub and Zonote product page to widen CVE-2020-35717 into its surrounding weakness, vendor, and product context.