Description
Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguised SVG content can be placed in another user's vault and execute stored cross-site scripting when the victim opens that vault. This issue is fixed in version 0.16.0.
Published: 2026-09-17
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross-site scripting and unauthorized file write across user vaults
Action: Immediate Patch
AI Analysis

Impact

A specially crafted ZIP file can include parent-directory traversal segments. An authenticated user who imports a ZIP vault can write files outside their own vault, including into other users’ vaults, overwriting existing files. If a disguised SVG file is placed in another user’s vault, opening that vault can trigger stored cross‑site scripting. The vulnerability therefore enables both data tampering and XSS, potentially compromising the confidentiality and integrity of other users’ data as well as inducing malicious code execution in victims’ browsers. The likely attack vector is an authenticated user uploading a malicious ZIP file through the app’s import feature. The description does not explicitly mention the exact path of exploitation, so this inference is drawn from the stated behaviour of the import routine. Affected systems are instances of Many Notes developed by brufdev. Prior to version 0.16.0 any user possessing the import privilege could exercise this capability, whereas the issue is fixed starting with 0.16.0.

Affected Systems

The vulnerability applies to all installations of Many Notes produced by brufdev. Versions earlier than 0.16.0 are affected; 0.16.0 and later are considered fixed.

Risk and Exploitability

The CVSS score of 9.6 assigns a high severity, reflecting the ability to write arbitrary files and trigger XSS. The EPSS score being less than 1% suggests that, as of the latest data, the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with import rights; no additional privileged conditions are described. The combination of high impact and low occurrence probability frames a scenario where organizations should still prioritize to eliminate the potential for user‑to‑user data poisoning and cross‑site scripting.

Generated by OpenCVE AI on September 19, 2026 at 03:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the application to version 0.16.0 or later, which contains the fix for the ZIP import traversal.
  • Restrict the ZIP vault import functionality to trusted users only or temporarily disable it for non‑admin accounts until a patch is applied.
  • Conduct a scan of existing vaults for SVG files that may have been injected as a result of the vulnerability and sanitize or remove them to mitigate stored XSS risks.

Generated by OpenCVE AI on September 19, 2026 at 03:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Brufdev
Brufdev many Notes
Vendors & Products Brufdev
Brufdev many Notes

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguised SVG content can be placed in another user's vault and execute stored cross-site scripting when the victim opens that vault. This issue is fixed in version 0.16.0.
Title Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Brufdev Many Notes
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:22.718Z

Reserved: 2026-06-11T18:24:35.096Z

Link: CVE-2026-54053

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:05.231Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T18:16:45.857

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')