Description

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits password: "null" to the internal login endpoint receives a valid session for that user. The bypass is unauthenticated and requires no user interaction. This issue has been patched in version 0.19.3.

INFO

Published Date :

2026-05-04T17:42:32.428Z

Last Modified :

2026-05-04T20:20:53.632Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-41571 vulnerability.

Vendors Products
Enchant97
  • Note-mark
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-41571.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact