CVE-2026-40262 is a stored cross-site scripting (XSS) vulnerability affecting Note Mark, an open-source note-taking application in versions 0.19.1 and prior. The vulnerability exists in the asset delivery handler, which serves uploaded files with insufficient content-type validation and missing security headers, allowing browsers to sniff and execute active content such as HTML or SVG files containing embedded JavaScript. The vulnerability carries a CVSS 3.1 score of 8.7 (HIGH) with a network attack vector, low complexity, and low privilege requirements. An authenticated user can upload malicious HTML or SVG files as note assets, which execute in the application's security context when accessed by a victim, potentially compromising the victim's authenticated session and enabling unauthorized API actions. The attack requires user interaction (victim must navigate to the asset URL) but impacts the confidentiality and integrity of affected users' data. There is no evidence of active exploitation in the wild, with an EPSS score of 0.00011 indicating minimal prevalence among disclosed vulnerabilities. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no publicly available exploit code is currently documented. The issue has been remediated in version 0.19.2, and organizations using Note Mark should update immediately to address this high-severity flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Enchant97 | Note-Mark | < 0.19.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.