Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pxf8-6wqm-r6hh | Note Mark: OIDC-registered users authenticated by submitting password "null" |
Mon, 04 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Enchant97
Enchant97 note-mark |
|
| Vendors & Products |
Enchant97
Enchant97 note-mark |
Mon, 04 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits password: "null" to the internal login endpoint receives a valid session for that user. The bypass is unauthenticated and requires no user interaction. This issue has been patched in version 0.19.3. | |
| Title | Note Mark: OIDC-registered users authenticated by submitting password "null" | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-04T20:20:53.632Z
Reserved: 2026-04-21T14:15:21.957Z
Link: CVE-2026-41571
Updated: 2026-05-04T20:20:41.523Z
Status : Deferred
Published: 2026-05-04T18:16:29.600
Modified: 2026-05-06T21:25:48.847
Link: CVE-2026-41571
No data.
OpenCVE Enrichment
Updated: 2026-05-04T19:30:02Z
Github GHSA