Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3gr9-485j-v4xf | Note Mark: Unauthenticated read of notes and assets in soft-deleted public books |
Mon, 04 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Enchant97
Enchant97 note-mark |
|
| Vendors & Products |
Enchant97
Enchant97 note-mark |
Mon, 04 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note ID or the slug path retain access. GORM's soft-delete scope does not reach the raw "JOIN books ..." clauses used by the note and asset queries. This issue has been patched in version 0.19.3. | |
| Title | Note Mark: Unauthenticated read of notes and assets in soft-deleted public books | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-04T19:39:55.331Z
Reserved: 2026-04-21T14:15:21.957Z
Link: CVE-2026-41572
Updated: 2026-05-04T19:39:51.722Z
Status : Deferred
Published: 2026-05-04T18:16:29.763
Modified: 2026-05-07T15:43:39.827
Link: CVE-2026-41572
No data.
OpenCVE Enrichment
Updated: 2026-05-04T20:30:07Z
Github GHSA