01 Record index
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
Upgrade to NoteGen 0.32.0 or later. The fix removes shell:allow-execute entries that permitted bash, python, and python3 with attacker-controlled arguments from the default Tauri capabilities, closing the webview-to-OS command execution path.