---
id: CVE-2026-105785
title: Joplin Server password reset accepts tokens issued for unrelated purposes
summary: >-
  Joplin is an open source note-taking and to-do application that organises
  notes and lists into notebooks. Prior to Joplin Server 3.7.2,
  packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation,
  email-change, and passwor…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-620
  - CWE-640
vendor: laurent22
product: joplin
affected:
  - joplin < 3.7.2
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T23:12:45.286Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-105785'
references:
  - url: >-
      https://github.com/laurent22/joplin/security/advisories/GHSA-8qm8-mp6h-qf35
    label: >-
      https://github.com/laurent22/joplin/security/advisories/GHSA-8qm8-mp6h-qf35
  - url: 'https://github.com/laurent22/joplin/pull/16274'
    label: 'https://github.com/laurent22/joplin/pull/16274'
  - url: >-
      https://github.com/laurent22/joplin/commit/7766eefa11fa006b6a1971da24e0c820cf1d2118
    label: >-
      https://github.com/laurent22/joplin/commit/7766eefa11fa006b6a1971da24e0c820cf1d2118
tags:
  - cve.org
ingestedAt: '2026-10-05T23:36:21.187Z'
---

## Overview

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.

## Affected

- `joplin < 3.7.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
