CVE-2026-105784Medium· 4.6▾ SunlitJoplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.
joplin < 3.7.13Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105783High· 8.0Joplin Web Clipper pairing allows cross-origin theft of a permanent API token
CVE-2026-105786High· 8.5Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier
CVE-2026-59814High· 7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-46650Medium· 4.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55105High· 7.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2022-35131Critical· 9.0Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.