CVE-2026-46650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in laurent22 joplin
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. A low-privileged Joplin Server user can publish the crafted HTML note as a public share. In the current build, ordinary left-click is blocked; demonstrated execution requires middle-click or Open in new tab in an older or non-hardened browser because current Chrome and Firefox block javascript: new-tab navigation. When execution succeeds, the script runs in the Joplin Server origin, can read page-visible content, and can make authenticated same-origin requests when the victim is signed in. This issue is fixed in version 3.7.2.
AI Analysis
Technical Summary
Joplin, an open source note-taking application, contained an XSS vulnerability (CWE-79) in the isAcceptedUrl() function within packages/renderer/htmlUtils.ts. The function used an unanchored regular expression to validate internal resource URLs, which allowed javascript: URLs containing a specific 32-character path fragment to bypass validation and be embedded in HTML notes. A low-privileged Joplin Server user could publish such a crafted note as a public share. While modern browsers block javascript: URLs on ordinary left-click, exploitation is possible via middle-click or 'Open in new tab' in older or non-hardened browsers. When executed, the malicious script runs in the Joplin Server origin, can read visible page content, and perform authenticated same-origin requests if the victim is signed in. This vulnerability was resolved in Joplin version 3.7.2.
Potential Impact
An attacker with low privileges on a Joplin Server can publish a malicious HTML note containing a crafted javascript: URL that may execute script code in the context of the Joplin Server origin. This can lead to disclosure of page-visible content and allow the attacker to perform authenticated requests on behalf of the victim if they are signed in. The attack requires user interaction and is mitigated by modern browser protections against javascript: URLs on left-click navigation.
Mitigation Recommendations
This vulnerability is fixed in Joplin version 3.7.2. Users and administrators should upgrade to version 3.7.2 or later to remediate this issue. No additional mitigations are required if the update is applied. If upgrading is not immediately possible, users should be cautious about opening public shares in older or non-hardened browsers and avoid middle-click or 'Open in new tab' actions on links within shared notes.
CVE-2026-46650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in laurent22 joplin
Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. A low-privileged Joplin Server user can publish the crafted HTML note as a public share. In the current build, ordinary left-click is blocked; demonstrated execution requires middle-click or Open in new tab in an older or non-hardened browser because current Chrome and Firefox block javascript: new-tab navigation. When execution succeeds, the script runs in the Joplin Server origin, can read page-visible content, and can make authenticated same-origin requests when the victim is signed in. This issue is fixed in version 3.7.2.
CVSS v3.1
Score 4.4medium
Affected software
laurent22
joplin
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Joplin, an open source note-taking application, contained an XSS vulnerability (CWE-79) in the isAcceptedUrl() function within packages/renderer/htmlUtils.ts. The function used an unanchored regular expression to validate internal resource URLs, which allowed javascript: URLs containing a specific 32-character path fragment to bypass validation and be embedded in HTML notes. A low-privileged Joplin Server user could publish such a crafted note as a public share. While modern browsers block javascript: URLs on ordinary left-click, exploitation is possible via middle-click or 'Open in new tab' in older or non-hardened browsers. When executed, the malicious script runs in the Joplin Server origin, can read visible page content, and perform authenticated same-origin requests if the victim is signed in. This vulnerability was resolved in Joplin version 3.7.2.
Potential Impact
An attacker with low privileges on a Joplin Server can publish a malicious HTML note containing a crafted javascript: URL that may execute script code in the context of the Joplin Server origin. This can lead to disclosure of page-visible content and allow the attacker to perform authenticated requests on behalf of the victim if they are signed in. The attack requires user interaction and is mitigated by modern browser protections against javascript: URLs on left-click navigation.
Mitigation Recommendations
This vulnerability is fixed in Joplin version 3.7.2. Users and administrators should upgrade to version 3.7.2 or later to remediate this issue. No additional mitigations are required if the update is applied. If upgrading is not immediately possible, users should be cautious about opening public shares in older or non-hardened browsers and avoid middle-click or 'Open in new tab' actions on links within shared notes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-15T20:11:54.585Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab1a26455bf5e2cf580011b
Added to database: 09/21/2026, 21:32:20 UTC
Last enriched: 09/21/2026, 21:46:56 UTC
Last updated: 09/21/2026, 23:49:44 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.