CVE-2026-54053: Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults

Published Sep 17, 2026
·
Updated

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguised SVG content can be placed in another user's vault and execute stored cross-site scripting when the victim opens that vault. This issue is fixed in version 0.16.0.

Affected Software

1 affected component
Many Notes<0.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Many Notes to a version that resolves this vulnerability.

    Fixed in 0.16.0

Event History

Sep 17, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Many Notes user can exploit the vulnerable ZIP vault import. No victim interaction is required for the file-write portion; stored XSS can execute when another user opens the affected vault.

2

Which deployments are affected?

Many Notes versions prior to 0.16.0 are affected where ZIP vault import is available. The vulnerability is in the ZIP vault import processing path.

3

What can an attacker do?

An attacker can use parent-directory traversal entries in an imported archive to write files outside their own vault, including into other users' vaults and over existing files. They can also place disguised SVG content that triggers stored XSS when a victim opens the impacted vault.

4

What should be done if patching cannot happen immediately?

The provided information identifies ZIP vault import as the affected feature. Restricting access to that import capability can reduce exposure until upgrading to version 0.16.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203