CVE-2026-46650Medium· 4.4▾ SunlitJoplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs,…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. A low-privileged Joplin Server user can publish the crafted HTML note as a public share. In the current build, ordinary left-click is blocked; demonstrated execution requires middle-click or Open in new tab in an older or non-hardened browser because current Chrome and Firefox block javascript: new-tab navigation. When execution succeeds, the script runs in the Joplin Server origin, can read page-visible content, and can make authenticated same-origin requests when the victim is signed in. This issue is fixed in version 3.7.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59814High· 7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55105High· 7.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2022-35131Critical· 9.0Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CVE-2026-55210High· 7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59815Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55179Medium· 6.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks