FixVibe

high

Remote Code Execution in Note Mark via Path Traversal (CVE-2026-44522)

Note Mark backend versions before 0.19.4 are affected by an asset-name path traversal issue that can impact administrator data exports. FixVibe GitHub repo scans flag affected Note Mark backend versions.

CVE-2026-44522GHSA-g49p-4qxj-88v3CWE-20CWE-22

Attacker Impact

Affected Note Mark backend versions can store attacker-controlled asset names from authenticated note activity. If an administrator later runs a data export with those stored names, the export process can write files outside the intended export directory [S1]. In deployments where that export runs with broad filesystem privileges, this can become arbitrary file write and may lead to code execution [S2].

Root Cause

The backend did not enforce safe basename-only asset names before persisting them, and export code later reused the stored names while constructing filesystem paths [S1]. GitHub Advisory Database tracks this as CVE-2026-44522 / GHSA-g49p-4qxj-88v3 for the Go package github.com/enchant97/note-mark/backend, with patched versions available in Note Mark 0.19.4 and the corresponding fixed Go pseudo-version [S1].

Concrete Fixes

  • Upgrade Note Mark: Update the backend to Note Mark 0.19.4 or 0.0.0-20260501152243-db3f72bff780 or later, then rebuild and redeploy the backend and any export tooling [S1].
  • Validate asset names: Accept only safe basename-style asset names and reject path separators or traversal markers before storing metadata [S1].
  • Harden exports: Normalize export paths defensively and ensure each output path remains inside the intended export directory before writing files [S1].
  • Limit filesystem impact: Run the application and export workflow with least-privilege filesystem access so a path-handling mistake cannot write broadly across the host [S2].

Covered by FixVibe

FixVibe's GitHub repo scans flag Go manifest or lockfile entries that resolve github.com/enchant97/note-mark/backend to a version affected by CVE-2026-44522 / GHSA-g49p-4qxj-88v3, with upgrade guidance for the deployed backend.