Product: api.amplenote.com/v4 + images.amplenote.com
Type: Access control / Revocation bypass
Summary
When a private note is shared with another user, its image attachments are served through URLs such as:
https:
These URLs remain accessible after the collaborator's access to the note is revoked. The note itself correctly becomes inaccessible (404), but previously issued attachment URLs continue returning 200.
The media URLs are also accessible without authentication, meaning anyone who obtains a previously issued URL can continue accessing the attachment.
Steps to Reproduce
Account A creates a private note and uploads an image.
Account A shares the note with Account B.
From Account B, confirm:
GET /v4/notes/{note_uuid} → 200
Attachment URL → 200
Account A revokes Account B's access:
DELETE /v4/notes/{note_uuid}/shares/{B}
From Account B, confirm:
GET /v4/notes/{note_uuid} → 404
GET /v4/notes/{note_uuid}/media → 404
GET /v4/notes/{note_uuid}/content → 404
Previously obtained attachment URL → 200
The attachment can also be fetched without authentication.
Impact
A collaborator who has been removed can retain access to private note attachments indefinitely. Anyone who later obtains the stale URL can also access the attachment, even though access to the underlying note has been revoked.
This can expose sensitive images such as scans, screenshots, documents, or whiteboards.
Suggested Remediation
Media URLs should respect the current authorization state of the associated note. Consider using short-lived signed URLs or an authorization layer that checks the user's current note/share permissions, and invalidate or rotate existing media URLs when access is revoked or the note is deleted.