CVE-2026-49453High· 7.0▾ MidnightPoC availableJoplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or pa…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Exploit / PoC code exists
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or path-separator characters. BaseItem.unserialize() stores the unvalidated fields, resourceFilename() concatenates them into a destination path, and ResourceFetcher writes the attacker-controlled resource blob outside the resource directory during background synchronization. An attacker with write access to a configured sync target or shared notebook can create or overwrite files at an attacker-chosen existing path without user interaction. This issue is fixed in versions 3.6.15 and 3.7.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59816Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59814High· 7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55179Medium· 6.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-49450High· 7.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-55210High· 7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-59815Medium· 4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks