← Zuruck zu CVEs
CVE-2026-40265
MEDIUM5.9
Beschreibung
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the backend query does not verify ownership or book visibility. An unauthenticated user who knows a valid note ID and asset ID can retrieve the full contents of private note assets without authentication, regardless of whether the associated book is public or private. This issue has been fixed in version 0.19.2.
CVE Details
CVSS v3.1 Bewertung5.9
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatHIGH
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht4/17/2026
Zuletzt geandert4/17/2026
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-862
Referenzen
https://github.com/enchant97/note-mark/commit/6593898855add151eb9965d96998b05e14c62026(security-advisories@github.com)
https://github.com/enchant97/note-mark/releases/tag/v0.19.2(security-advisories@github.com)
https://github.com/enchant97/note-mark/security/advisories/GHSA-p5w6-75f9-cc2p(security-advisories@github.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.