Product: api.amplenote.com — v4 API
Endpoint: POST /v4/accounts/media
Classification: Broken authorization / unrestricted resource creation
Summary
Any authenticated Amplenote account can create media objects on images.amplenote.com without associating them with a valid note.
The note_uuid parameter is optional and is not validated. Arbitrary, nonexistent, or another user's private note UUID can be supplied, or the field can be omitted entirely, while the API still returns 201 and issues a presigned upload URL plus a permanent public CDN URL.
The resulting image can then be uploaded and retrieved anonymously without authentication.
Steps to Reproduce
Using any authenticated Amplenote account, send:
POST /v4/accounts/media
Authorization: Bearer <token>
Content-Type: application/json
{"note_uuid":"<another user's private note UUID>","type":"image/png","size":100}
The same request succeeds with:
{"note_uuid":"00000000-0000-4000-8000-000000000000","type":"image/png","size":100}
or:
{"note_uuid":"not-a-uuid","type":"image/png","size":100}
or even without note_uuid:
{"type":"image/png","size":100}
All variants return 201 with a new media UUID, presigned S3 URL, and public URL such as:
https:
Upload the declared image to the returned presigned URL:
PUT <presigned-url>
Content-Type: image/png
<image bytes>
The upload succeeds (200).
The resulting object can then be retrieved without authentication:
GET https:
Response:
200 OK
Content-Type: image/png
Observed Impact
Media objects can be created without a valid note association.
Arbitrary/foreign note_uuid values are accepted without authorization checks.
Each successful request generates a new publicly accessible media object.
The resulting CDN objects are anonymously readable.
No effective minting rate limit was observed during testing.
No per-account storage quota was observed.
Objects do not appear to have a normal note/account lifecycle and remain accessible after creation.
This creates a potential storage and bandwidth/egress abuse vector, where a single account can continuously create publicly hosted image objects on Amplenote infrastructure.
The tested endpoint does not provide access to another user's note contents; the referenced note UUID is simply accepted as metadata. Cross-account access to the actual note/media APIs remained properly restricted.
Remediation
Require note_uuid if uploads are intended to belong to notes.
Verify that the authenticated user owns or has appropriate access to the referenced note.
If standalone account media is intended, explicitly associate objects with the creating account.
Enforce per-account storage quotas and upload/minting rate limits.
Add lifecycle/expiration and deletion mechanisms for otherwise-unreferenced media objects.
Ensure account deletion and note deletion/revocation clean up associated media where appropriate.