PT-2026-96248 · Unknown · Joplin-Desktop
CVE-2026-49450
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
7.1
High
| Vector | AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Joplin Desktop for Windows versions prior to 3.7.2
Description
Joplin Desktop for Windows fails to include the
publisherName in the packages/app-desktop/package.json file. This omission causes the NsisUpdater.verifySignature() function to skip the comparison between the Authenticode signer of a downloaded update and the official Joplin signer. An attacker controlling the update delivery path can replace the update metadata and installer. Consequently, the client may accept an installer that is unsigned or signed by a different publisher upon user approval. Successful exploitation allows the execution of arbitrary code with user privileges, potentially compromising notes, credentials, and local data.Recommendations
Update to version 3.7.2.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Joplin-Desktop