Home

Description

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.

PUBLISHED Reserved 2026-05-06 | Published 2026-05-14 | Updated 2026-05-15 | Assigner GitHub_M




CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Problem types

CWE-326: Inadequate Encryption Strength

CWE-345: Insufficient Verification of Data Authenticity

Product status

< 0.19.4
affected

References

github.com/...e-mark/security/advisories/GHSA-q6mh-rqwh-g786 exploit

github.com/...e-mark/security/advisories/GHSA-q6mh-rqwh-g786

cve.org (CVE-2026-44523)

nvd.nist.gov (CVE-2026-44523)

Download JSON