---
id: CVE-2026-97868
title: A security vulnerability has been detected in sheshbabu zen up to 1.5.0
summary: >-
  A security vulnerability has been detected in sheshbabu zen up to 1.5.0.
  Affected by this issue is the function dangerouslySetInnerHTML of the file
  features/notes/NotesEditor.jsx of the component Note Editor. The manipulation
  leads to cr…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: sheshbabu
product: zen
affected:
  - zen 1.0
  - zen 1.1
  - zen 1.2
  - zen 1.3
  - zen 1.4
  - zen 1.5.0
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T18:17:34.527'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97868'
references:
  - url: >-
      https://ctf-n0el4kls.notion.site/Store-XSS-in-sheshbabu-zen-3ae41990f44780dbadb6e6af57e6f833
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-97868'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/911735'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409884'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409884/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T17:10:09.749958Z'
ingestedAt: '2026-09-25T16:12:08.733Z'
---

## Overview

A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/notes/NotesEditor.jsx of the component Note Editor. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
