CVE-2026-44523Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-326CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-08: 2Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-08: 205-08
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulert@vulert_official
    Patch

    v🚨 CVE-2026-44523 in Note Mark exposes a Weak JWT Secret vulnerability that could lead to account takeover. Update to the patched version and use strong JWT secret management. 🔎 https://vulert.com/vuln-db/CVE-2026-44523 #CyberSecurity #CVE #JWT #Vulert https://t.co/BfoqcQajUI

    Post summary

    CVE-2026-44523 in Note Mark exposes a weak JWT secret vulnerability; users should apply the patched version and strengthen JWT secret management to mitigate potential account takeover.

    0001051
    125 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Note Mark, Weak JWT Secret, #CVE-2026-44523 (Critical) https://dailycve.com/note-mark-weak-jwt-secret-cve-2026-44523-critical/

    Post summary

    The post links to an article announcing a newly disclosed critical CVE-2026-44523 in Note Mark, highlighting a weak JWT secret vulnerability, but provides no details on exploitation, tool availability, or mitigation.

    0000034
    196 followersView on X

Explore more