Skip to main content

CVE-2026-46650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in laurent22 joplin

0
Medium
VulnerabilityCVE-2026-46650cvecve-2026-46650cwe-79
Published: 09/21/2026 (09/21/2026, 21:16:12 UTC)
Source: CVE Database V5
Vendor/Project: laurent22
Product: joplin

Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. A low-privileged Joplin Server user can publish the crafted HTML note as a public share. In the current build, ordinary left-click is blocked; demonstrated execution requires middle-click or Open in new tab in an older or non-hardened browser because current Chrome and Firefox block javascript: new-tab navigation. When execution succeeds, the script runs in the Joplin Server origin, can read page-visible content, and can make authenticated same-origin requests when the victim is signed in. This issue is fixed in version 3.7.2.

CVSS v3.1

Score 4.4medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected software

laurent22

joplin

Affected versions
<3.7.2
GitHub Actionsmore threats →ai
laurent22/joplin
pkg:github/laurent22/joplin
Affected versions
<3.7.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 21:46:56 UTC

Technical Analysis

Joplin, an open source note-taking application, contained an XSS vulnerability (CWE-79) in the isAcceptedUrl() function within packages/renderer/htmlUtils.ts. The function used an unanchored regular expression to validate internal resource URLs, which allowed javascript: URLs containing a specific 32-character path fragment to bypass validation and be embedded in HTML notes. A low-privileged Joplin Server user could publish such a crafted note as a public share. While modern browsers block javascript: URLs on ordinary left-click, exploitation is possible via middle-click or 'Open in new tab' in older or non-hardened browsers. When executed, the malicious script runs in the Joplin Server origin, can read visible page content, and perform authenticated same-origin requests if the victim is signed in. This vulnerability was resolved in Joplin version 3.7.2.

Potential Impact

An attacker with low privileges on a Joplin Server can publish a malicious HTML note containing a crafted javascript: URL that may execute script code in the context of the Joplin Server origin. This can lead to disclosure of page-visible content and allow the attacker to perform authenticated requests on behalf of the victim if they are signed in. The attack requires user interaction and is mitigated by modern browser protections against javascript: URLs on left-click navigation.

Mitigation Recommendations

This vulnerability is fixed in Joplin version 3.7.2. Users and administrators should upgrade to version 3.7.2 or later to remediate this issue. No additional mitigations are required if the update is applied. If upgrading is not immediately possible, users should be cautious about opening public shares in older or non-hardened browsers and avoid middle-click or 'Open in new tab' actions on links within shared notes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-15T20:11:54.585Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ab1a26455bf5e2cf580011b

Added to database: 09/21/2026, 21:32:20 UTC

Last enriched: 09/21/2026, 21:46:56 UTC

Last updated: 09/21/2026, 23:49:44 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses