> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# PoC Released - CVE-2024-41662 Markdown XSS leads to RCE in VNote version <=3.18.1
- URL: https://darkwebinformer.com/poc-released-cve-2024-41662-markdown-xss-leads-to-rce-in-vnote-version-3-18-1/
- Published: 2024-07-25T17:42:06.000Z
- Updated: 2025-09-04T22:28:21.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

Markdown XSS leads to RCE in VNote version <=3.18.1

**Severity :** **High** (**8.6**)

**CVSS score :** `CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H`

## Summary :

[](https://github.com/sh3bu/CVE-2024-41662?tab=readme-ov-file#summary-)

A **Cross-Site Scripting (XSS)** vulnerability was identified in the Markdown rendering functionality of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary JavaScript code, potentially leading to **Remote Code Execution (RCE)**.

Credit: Shebu on X; <https://x.com/%5Fsh3bu>

More below!

[GitHub - sh3bu/CVE-2024-41662: Markdown XSS leads to RCE in VNote version <=3.18.1Markdown XSS leads to RCE in VNote version <=3.18.1 - sh3bu/CVE-2024-41662![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubsh3bu![](https://opengraph.githubassets.com/93536a4e3d2053942990dc5fcb704e97a80aa8a4ba28980a6dcf6bd038df5005/sh3bu/CVE-2024-41662)](https://github.com/sh3bu/CVE-2024-41662)