Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark
Published Sep 3, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.42%
Description
Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the service runs the query with Unscoped() (bypassing GORM's soft-delete scope) but keeps the read-authorization clause as "owner_id = ? OR is_public = ?". As a result, any unauthenticated caller can enumerate the metadata of soft-deleted ("trashed") notes belonging to any public book — notes the owner explicitly deleted and expected to be removed from public view. This issue has been patched in version 0.19.5.
Affected products
-
- Version < 0.19.5StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/enchant97/note-mark/backend
Go
Introduced 0 Fixed 0.0.0-20260601210758-9c9b72740f22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/enchant97/note-mark/backend | 0 | 0.0.0-20260601210758-9c9b72740f22 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70529 Advisory
- https://github.com/advisories/GHSA-588f-fvcv-xhvf Advisory
- https://github.com/enchant97/note-mark/commit/9c9b72740f22a06131a8f64b53bb08e3b05b81a6 x_refsource_MISC
- https://github.com/enchant97/note-mark/releases/tag/v0.19.5 x_refsource_MISC
- https://github.com/enchant97/note-mark/security/advisories/GHSA-588f-fvcv-xhvf exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70529 | Advisory | |
| https://github.com/advisories/GHSA-588f-fvcv-xhvf | Advisory | |
| https://github.com/enchant97/note-mark/commit/9c9b72740f22a06131a8f64b53bb08e3b05b81a6 | x_refsource_MISC | |
| https://github.com/enchant97/note-mark/releases/tag/v0.19.5 | x_refsource_MISC | |
| https://github.com/enchant97/note-mark/security/advisories/GHSA-588f-fvcv-xhvf | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.