Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40262

29
FAUCET Score

CVE-2026-40262 is a stored cross-site scripting (XSS) vulnerability affecting Note Mark, an open-source note-taking application in versions 0.19.1 and prior. The vulnerability exists in the asset delivery handler, which serves uploaded files with insufficient content-type validation and missing security headers, allowing browsers to sniff and execute active content such as HTML or SVG files containing embedded JavaScript. The vulnerability carries a CVSS 3.1 score of 8.7 (HIGH) with a network attack vector, low complexity, and low privilege requirements. An authenticated user can upload malicious HTML or SVG files as note assets, which execute in the application's security context when accessed by a victim, potentially compromising the victim's authenticated session and enabling unauthorized API actions. The attack requires user interaction (victim must navigate to the asset URL) but impacts the confidentiality and integrity of affected users' data. There is no evidence of active exploitation in the wild, with an EPSS score of 0.00011 indicating minimal prevalence among disclosed vulnerabilities. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no publicly available exploit code is currently documented. The issue has been remediated in version 0.19.2, and organizations using Note Mark should update immediately to address this high-severity flaw.

Impacted Technologies

VendorProductVersion(s)CPE
Enchant97Note-Mark
< 0.19.2CNA affected

CVSS Data

CVSS version used by this source: 3.1

8.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 29th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/enchant97/note-mark/backendFixed in: 0.0.0-20260411145018-6bb62842ccb9

Vendor Advisories (1)

goGHSA-9pr4-rf97-79qhhigh

Note Mark has Stored XSS via Unrestricted Asset Upload

Apr 13, 2026

References

github.com / enchant97/note-mark/commit/6bb62842ccb956870b9bf183629eba95e326e5e3
github.com / enchant97/note-mark/releases/tag/v0.19.2
github.com / enchant97/note-mark/security/advisories/GHSA-9pr4-rf97-79qh