Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/laurent22/joplin

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. A low-privileged Joplin Server user can publish the crafted HTML note as a public share. In the current build, ordinary left-click is blocked; demonstrated execution requires middle-click or Open in new tab in an older or non-hardened browser because current Chrome and Firefox block javascript: new-tab navigation. When execution succeeds, the script runs in the Joplin Server origin, can read page-visible content, and can make authenticated same-origin requests when the victim is signed in. This issue is fixed in version 3.7.2.

Join the discussion

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists for the caller, without requiring ShareUserStatus.Accepted. A low-privileged authenticated user with a pending folder-share invitation can create an item under the share ID, and ShareModel.updateSharedItems3() propagates the injected content to the owner and accepted participants before the attacker accepts the invitation. This issue is fixed in version 3.7.7.

Join the discussion

Joplin Server versions prior to 3.7.2 contain an authentication bypass vulnerability in the SSO login process. The UserModel.ssoLogin() method does not verify the is_external flag when matching accounts by IdP-asserted email. This allows an attacker with a valid IdP session to impersonate a local user and gain unauthorized access to that user's notes, files, and settings without knowing their password. The issue is resolved in version 3.7.2.

Join the discussion

Joplin Server versions prior to 3.7.7 contain a cross-site scripting (XSS) vulnerability in the GET /shares/:id?resource_id= route. A low-privileged user can publish an empty-title SVG image attachment with attacker-controlled script code that executes when a victim opens the public share. By default, the script runs in the Joplin Server application origin, enabling access to same-origin data and session-based actions if the victim is authenticated. This vulnerability is fixed in version 3.7.7.

Join the discussion

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer into note output without sanitizing it. A malicious Fountain code block can therefore execute script when Fountain rendering is enabled in desktop or mobile clients, or when a note is published through Joplin Server where Fountain rendering is enabled by default. The script can read content subsequently loaded in the reused note viewer or, when published notes are served from the same domain as server content, access data available to an authenticated browser in the server origin. This issue is fixed in versions 3.6.15 and 3.7.2.

Join the discussion

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.

Join the discussion

Joplin Server versions prior to 3.7.2 have an authorization bypass vulnerability in the GET /items/:id/content route. This flaw allows any authenticated user to access note or item content belonging to other users by supplying or guessing the internal server ID of those items. The vulnerability occurs because the server does not verify ownership or access rights before returning the content. This issue is fixed in version 3.7.2.

Join the discussion

Joplin Server versions prior to 3.7.7 with transcription enabled are vulnerable to a path traversal issue. Authenticated users can manipulate the transcription job ID to escape the intended directory path, causing the server to proxy requests to unintended backend endpoints. This may expose internal administrative, health, or configuration data. The vulnerability is fixed in version 3.7.7.

Join the discussion

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note author to place a \href URL into rendered output without passing Joplin's normal URL allowlist. On Windows, clicking a link whose target is an attacker-controlled UNC path causes pathExists() to initiate SMB authentication and disclose the current user's NTLMv2 challenge-response without a warning. The unfiltered URL can also invoke other registered URL handlers, but the credential disclosure through KaTeX \href is the distinguishing demonstrated impact. This issue is fixed in version 3.7.2.

Join the discussion

Joplin before versions 3.6.15 and 3.7.2 contains an improper input validation vulnerability where synchronized resource metadata fields can include directory traversal characters. This allows an attacker with write access to a sync target or shared notebook to write files outside the intended resource directory without user interaction. The issue is fixed in versions 3.6.15 and 3.7.2.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:github/laurent22/joplin
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses