Back

CRITICAL

Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery

Published May 14, 2026

Description

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 14, 2026
Updated May 15, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated May 15, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published May 14, 2026
Updated May 15, 2026
Exploited since n/a
EUVD-2026-30367 GHSA-Q6MH-RQWH-G786