CVE-2026-101004 NotionNext 身份认证缺失漏洞
影响攻击者可未授权调用缓存清理接口,导致缓存被恶意刷新或拒绝服务
NotionNext 的 pages/api/cache.js 中 cleanCache 函数存在认证缺失问题。攻击者可通过操纵 token 参数绕过认证,远程触发缓存清理操作。该漏洞在 4.1.0 至 4.9.5.2 版本中可被未授权利用,4.9.5.7 至 4.10.10 版本仅在设置了 CACHE_REVALIDATION_TOKEN 时才受保护。
影响范围
NotionNext 4.1.0 至 4.10.10 版本受影响;其中 4.1.0-4.9.5.2 完全无方法校验,4.9.5.7-4.10.10 默认部署下保护未生效。
漏洞详情
该漏洞属于认证缺失(CWE-306)类型。cleanCache 接口未正确校验请求方法或 token,导致未认证用户可调用缓存清理功能。在旧版本中完全缺少方法检查,新版本中虽有守卫逻辑,但仅在配置了 CACHE_REVALIDATION_TOKEN 环境变量时才生效,默认部署仍处于无保护状态。
利用条件与风险
攻击者可远程发起请求,无需认证即可触发缓存清理,可能造成缓存频繁失效、性能下降甚至拒绝服务。利用门槛低,但影响限于缓存层面,危害程度中等。
修复建议
厂商未回应,暂无官方补丁。建议用户手动在 cleanCache 接口中强制校验请求方法及 token,或通过反向代理限制 /api/cache 路径的访问来源,并确保设置 CACHE_REVALIDATION_TOKEN 环境变量。
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 – 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 – 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.