CVE-2026-49450High· 7.1▾ MidnightPoC availableJoplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Exploit / PoC code exists
Last analysed / modified upstream
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded update's Authenticode signer with Joplin's signer. An attacker who controls the update delivery path can replace the update metadata and installer, and the client accepts an installer signed by another publisher or left unsigned after the user approves installation. Successful exploitation runs attacker-controlled code with the user's privileges and can compromise notes, credentials, and local data. This issue is fixed in version 3.7.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59814High· 7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55179Medium· 6.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59816Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-49453High· 7.0Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55210High· 7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59815Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks