MEDIUM
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books
Published May 4, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.33%
Description
Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note ID or the slug path retain access. GORM's soft-delete scope does not reach the raw "JOIN books ..." clauses used by the note and asset queries. This issue has been patched in version 0.19.3.
Affected products
-
- Version < 0.19.3StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/enchant97/note-mark/backend
Go
Introduced 0 Fixed 0.0.0-20260417132843-d1bf845a2a2d
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/enchant97/note-mark/backend | 0 | 0.0.0-20260417132843-d1bf845a2a2d |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-3gr9-485j-v4xf Advisory
- https://github.com/enchant97/note-mark/commit/d1bf845a2a2df01e2eca6f556287db4ec6f773cf
- https://github.com/enchant97/note-mark/releases/tag/v0.19.3 x_refsource_MISC
- https://github.com/enchant97/note-mark/security/advisories/GHSA-3gr9-485j-v4xf exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-41572
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 4, 2026
Updated May 4, 2026
Reserved Apr 21, 2026
Link CVE-2026-41572
CISA Vulnrichment
GHSA-3GR9-485J-V4XF Updated May 4, 2026