CVE Explorer
CVE-2026-40265
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the backend query does not verify ownership or book visibility. An unauthenticated user who knows a valid note ID and asset ID can retrieve the full contents of private note assets without authentication, regardless of whether the associated book is public or private. This issue has been fixed i
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"note-mark","vendor":"enchant97","versions":[{"status":"affected","version":"< 0.19.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cec8a6a08b8fe1836a3019d1725a9d17eab5f3fa1e1a65b2713f7bed0346797d · sha256:6a2956f137a1837a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cec8a6a08b8fe1836a3019d1725a9d17eab5f3fa1e1a65b2713f7bed0346797d · sha256:6a2956f137a1837a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cec8a6a08b8fe1836a3019d1725a9d17eab5f3fa1e1a65b2713f7bed0346797d · sha256:6a2956f137a1837a… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/enchant97/note-mark/commit/6593898855add151eb9965d96998b05e14c62026","tags":["x_refsource_MISC"],"url":"https://github.com/enchant97/note-mark/commit/6593898855add151eb9965d96998b05e14c62026"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cec8a6a08b8fe1836a3019d1725a9d17eab5f3fa1e1a65b2713f7bed0346797d · sha256:6a2956f137a1837a… · /containers/cna/references/1
{"name":"https://github.com/enchant97/note-mark/releases/tag/v0.19.2","tags":["x_refsource_MISC"],"url":"https://github.com/enchant97/note-mark/releases/tag/v0.19.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cec8a6a08b8fe1836a3019d1725a9d17eab5f3fa1e1a65b2713f7bed0346797d · sha256:6a2956f137a1837a… · /containers/cna/references/2
{"name":"https://github.com/enchant97/note-mark/security/advisories/GHSA-p5w6-75f9-cc2p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/enchant97/note-mark/security/advisories/GHSA-p5w6-75f9-cc2p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cec8a6a08b8fe1836a3019d1725a9d17eab5f3fa1e1a65b2713f7bed0346797d · sha256:6a2956f137a1837a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.