Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/enchant97/note-mark/backend
  4. ›
  5. CVE-2026-40265

CVE-2026-40265: Note Mark has Broken Access Control on Asset Download

April 13, 2026 (updated April 24, 2026)

A broken access control vulnerability allows unauthenticated users to retrieve note assets directly from the asset download endpoint when they know both the note UUID and asset UUID. This exposes the full contents of private note assets without authentication, even when the associated book is not public.

References

  • github.com/advisories/GHSA-p5w6-75f9-cc2p
  • github.com/enchant97/note-mark
  • github.com/enchant97/note-mark/commit/6593898855add151eb9965d96998b05e14c62026
  • github.com/enchant97/note-mark/releases/tag/v0.19.2
  • github.com/enchant97/note-mark/security/advisories/GHSA-p5w6-75f9-cc2p
  • nvd.nist.gov/vuln/detail/CVE-2026-40265

Code Behaviors & Features

Detect and mitigate CVE-2026-40265 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20260411145023-6593898855ad

Fixed versions

  • 0.0.0-20260411145023-6593898855ad

Solution

Upgrade to version 0.0.0-20260411145023-6593898855ad or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

go/github.com/enchant97/note-mark/backend/CVE-2026-40265.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:19:28 +0000.