---
id: CVE-2026-105784
title: Joplin whiteboard card rendering allows CSS injection into application chrome
summary: >-
  Joplin is an open source note-taking and to-do application that organises
  notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a
  jsoncanvas fence causes the whiteboard text and file-node components in
  packages/app…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-79
vendor: laurent22
product: joplin
affected:
  - joplin < 3.7.13
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T23:11:35.029Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-105784'
references:
  - url: >-
      https://github.com/laurent22/joplin/security/advisories/GHSA-6h4j-86j4-x4q4
    label: >-
      https://github.com/laurent22/joplin/security/advisories/GHSA-6h4j-86j4-x4q4
  - url: 'https://github.com/laurent22/joplin/pull/16275'
    label: 'https://github.com/laurent22/joplin/pull/16275'
  - url: >-
      https://github.com/laurent22/joplin/commit/7fb9ec93e47cec39a548a76e03d7ad660ca0f123
    label: >-
      https://github.com/laurent22/joplin/commit/7fb9ec93e47cec39a548a76e03d7ad660ca0f123
  - url: 'https://github.com/laurent22/joplin/releases/tag/v3.7.13'
    label: 'https://github.com/laurent22/joplin/releases/tag/v3.7.13'
tags:
  - cve.org
ingestedAt: '2026-10-05T23:36:21.188Z'
---

## Overview

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.

## Affected

- `joplin < 3.7.13`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
