PT-2026-96248 · Unknown · Joplin-Desktop

CVE-2026-49450

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

7.1

High

VectorAV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joplin Desktop for Windows versions prior to 3.7.2
Description Joplin Desktop for Windows fails to include the publisherName in the packages/app-desktop/package.json file. This omission causes the NsisUpdater.verifySignature() function to skip the comparison between the Authenticode signer of a downloaded update and the official Joplin signer. An attacker controlling the update delivery path can replace the update metadata and installer. Consequently, the client may accept an installer that is unsigned or signed by a different publisher upon user approval. Successful exploitation allows the execution of arbitrary code with user privileges, potentially compromising notes, credentials, and local data.
Recommendations Update to version 3.7.2.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49450
GHSA-9WP7-HR9M-3273

Affected Products

Joplin-Desktop