CVE-2026-54053

critical

Description

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguised SVG content can be placed in another user's vault and execute stored cross-site scripting when the victim opens that vault. This issue is fixed in version 0.16.0.

References

https://github.com/brufdev/many-notes/security/advisories/GHSA-wg8j-9c2g-xh6r

https://github.com/brufdev/many-notes/releases/tag/v0.16.0

https://github.com/brufdev/many-notes/commit/1b3288fa9671002e72e38b7fcd5d226673ba0cae

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82335

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 9.6

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.00697