CVE-2026-105784: fallo de gravedad media en laurent22 joplin
Joplin whiteboard card rendering allows CSS injection into application chrome
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.6epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Productos afectados
laurent22 · joplinCVEs relacionadas — laurent22 joplin
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-27134HIGHPrivilege escalation in Joplin server via user patch endpointEPSS 2.2%CVE-2024-49362HIGHRemote Code Execution on click of <a> Link in markdown previewEPSS 1.0%CVE-2023-45673HIGHArbitrary code execution on click of PDF links in JoplinEPSS 1.0%CVE-2024-40643CRITICALJoplin has a parsing error leading to Cross-site Scripting (XSS)EPSS 0.8%CVE-2024-53268HIGHLack of validation on openExternal allows 1 click remote code execution in joplinEPSS 0.7%CVE-2025-27409HIGHJoplin Server Vulnerable to Path TraversalEPSS 0.6%