Executive brief
Many Notes is a web-based markdown note-taking application. An authenticated attacker can exploit the ZIP vault import feature to write files into other users' vaults by using archive filenames with directory traversal sequences. By uploading malicious SVG files, an attacker can execute JavaScript in another user's browser when they open the affected vault, leading to account compromise or data theft.
Technical details
The vulnerability is a path traversal flaw in the ZIP vault import handler (app/Actions/ProcessImportedVault.php) that fails to validate archive entry filenames for directory traversal sequences (e.g., "../"). An authenticated user can craft a ZIP archive with entries containing "../" segments to write files outside their own vault and into other users' vaults, including overwriting existing files. When combined with SVG uploads (which execute JavaScript), an attacker can place stored XSS payloads in another user's vault. The fix in version 0.16.0 adds strict validation to reject any archive entries containing path traversal sequences. Authentication is required, but the impact is high as it enables cross-user file manipulation and XSS attacks.
Affected products
- brufdev Many Notes prior to 0.16.0
Timeline
- 2026-09-17: disclosed
- 2026-05-25: patched: Fixed in version 0.16.0