PT-2026-96249 · Joplin · Joplin

CVE-2026-49453

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Joplin versions prior to 3.6.15 Joplin versions prior to 3.7.2
Description Joplin accepts synchronized resource metadata where the id or file extension contains path-separator or parent-directory characters. The BaseItem.unserialize() function stores these unvalidated fields, which are then concatenated into a destination path by resourceFilename(). Consequently, ResourceFetcher writes attacker-controlled resource blobs outside the intended resource directory during background synchronization. An attacker with write access to a shared notebook or a configured sync target can create or overwrite files at an arbitrary path without user interaction.
Recommendations Update to version 3.6.15. Update to version 3.7.2.

Exploit

Fix

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49453
GHSA-R24R-GP6H-CWGF

Affected Products

Joplin