Attacker Impact
Affected Note Mark backend versions can store attacker-controlled asset names from authenticated note activity. If an administrator later runs a data export with those stored names, the export process can write files outside the intended export directory [S1]. In deployments where that export runs with broad filesystem privileges, this can become arbitrary file write and may lead to code execution [S2].
Root Cause
The backend did not enforce safe basename-only asset names before persisting them, and export code later reused the stored names while constructing filesystem paths [S1]. GitHub Advisory Database tracks this as CVE-2026-44522 / GHSA-g49p-4qxj-88v3 for the Go package github.com/enchant97/note-mark/backend, with patched versions available in Note Mark 0.19.4 and the corresponding fixed Go pseudo-version [S1].
Concrete Fixes
- Upgrade Note Mark: Update the backend to Note Mark 0.19.4 or
0.0.0-20260501152243-db3f72bff780or later, then rebuild and redeploy the backend and any export tooling [S1]. - Validate asset names: Accept only safe basename-style asset names and reject path separators or traversal markers before storing metadata [S1].
- Harden exports: Normalize export paths defensively and ensure each output path remains inside the intended export directory before writing files [S1].
- Limit filesystem impact: Run the application and export workflow with least-privilege filesystem access so a path-handling mistake cannot write broadly across the host [S2].
Covered by FixVibe
FixVibe's GitHub repo scans flag Go manifest or lockfile entries that resolve github.com/enchant97/note-mark/backend to a version affected by CVE-2026-44522 / GHSA-g49p-4qxj-88v3, with upgrade guidance for the deployed backend.
