EUVD Vulnerability Catalog

EUVD-2026-82335

Severity: CRITICAL Base Score: 9.6 CVSS Version: 3.1

Vulnerability Description

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguised SVG content can be placed in another user's vault and execute stored cross-site scripting when the victim opens that vault. This issue is fixed in version 0.16.0.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Privileges Required (PR): Low
▪ User Interaction (UI): None
▪ Scope (S): Changed
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): None

Affected Vendors & Systems

Vendor brufdev

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

GitHub_M

EPSS Probability

0

Known Aliases
CVE-2026-54053
Published On

2026-09-17

Last Updated

2026-09-17