PT-2026-95020 · Unknown · Many Notes

·

CVE-2026-54053

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Many Notes versions prior to 0.16.0
Description The ZIP vault import feature in the app/Actions/ProcessImportedVault.php file allows archive filenames to contain parent-directory traversal segments. This enables an authenticated user to write arbitrary files outside their own vault and into the vaults of other users, which may include overwriting existing files. Additionally, an attacker can place disguised SVG content into another user's vault to execute stored cross-site scripting (XSS), a technique where malicious scripts are permanently stored on the server and executed in the victim's browser, when the victim opens the affected vault.
Recommendations Update to version 0.16.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54053
GHSA-WG8J-9C2G-XH6R

Affected Products

Many Notes