CVE-2024-23743: Low severity Notion Notion vulnerability

Published Jan 28, 2024
·
Updated

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."

Affected Software

2 affected components
All of the following
Notion Notion<=3.1.0
macOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Notion Desktop (macOS) to a version that resolves this vulnerability.

    Fixed in 3.1.0
  2. Configuration

    Disable or remove Electron features that allow running the application as a Node.js environment (the issue is described as occurring through RunAsNode and enableNodeClilnspectArguments when launched with nonstandard flags).

    Notion Desktop (Electron) RunAsNode = disable
  3. Configuration

    Disable or remove support for enableNodeClilnspectArguments so launching with nonstandard flags cannot turn the Electron app into a Node.js execution environment.

    Notion Desktop (Electron) enableNodeClilnspectArguments = disable

Event History

Jan 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-23743?

CVE-2024-23743 has been classified as a security vulnerability that allows code execution through manipulative application launching.

2

How do I fix CVE-2024-23743?

To mitigate CVE-2024-23743, ensure that Notion is updated to a version later than 3.1.0 to eliminate exposure to the vulnerability.

3

Who is affected by CVE-2024-23743?

Users of Notion on macOS versions up to 3.1.0 are affected by CVE-2024-23743.

4

What allows the exploitation of CVE-2024-23743?

CVE-2024-23743 can be exploited by launching the Notion Desktop application with nonstandard flags turning it into a Node.js environment.

5

Is there a proof of concept for CVE-2024-23743?

Yes, reports indicate that there are proof of concept exploits available for CVE-2024-23743 demonstrating its potential impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203