CVE-2026-40262General

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte detection for content type, which does not identify text-based formats such as HTML, SVG, or XHTML. These files are served with an empty Content-Type, no X-Content-Type-Options: nosniff header, and inline disposition, allowing browsers to sniff and render active content. An authenticated user can upload an HTML or SVG file containing JavaScript as a note asset, and when a victim navigates to the asset URL, the script executes under the application's origin with access to the victim's authenticated session and API actions. This issue has been fixed in version 0.19.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-17)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-15: 1Mentions · 2026-04-17: 2Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 204-1504-17
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-151
Patch1
2026-04-172
General2
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-40262 Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte de… https://www.cve.org/CVERecord?id=CVE-2026-40262

    Post summary

    CVE-2026-40262 affects the Note Mark note-taking app by allowing inline serving of uploaded files that rely on magic-byte checks. No PoC, exploit, or patch information is presented.

    0000066
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40262 Cross-Site Scripting via Unsafe Asset Delivery in Note Mark 0.19.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40262

    Post summary

    The post cites CVE-2026-40262, stating it is a Cross‑Site Scripting vulnerability in Note Mark 0.19.1, but provides no PoC, exploit code, or fix details.

    0000039
    4.0K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    Command injection in Composer's Performance driver affects millions of PHP deployments globally. Critical to patch before these CVE-2026-40262/40176 move from "no exploitation" to active campaigns. Composer dependency chains make this especially dangerous in enterprise environments: https://vulntracker.io

    Post summary

    The post announces command injection vulnerabilities in Composer’s Performance driver, lists CVE‑2026‑40262 and 40176, stresses the need to patch before potential in‑the‑wild exploitation, and provides no PoC or exploit details.

    00000134
    538 followersView on X

Explore more