Abdo Hasani reports:
Imported note HTML may execute inside an embedded image-occlusion
document that retains the editor profile's desktop API credentials. This could
cross the boundary between untrusted note content and privileged desktop
operations.
An improper path validation vulnerability allows an attacker to
execute arbitrary code on a victim's system when they interact with a malicious
flashcard deck. This vulnerability is triggered when a user right-clicks an
image within the editor and selects the "Open image" action; if an embedded
"<img>" tag contains a path with a dangerous extension in its src attribute,
the operating system may execute the file.