PT-2026-96249 · Joplin · Joplin
CVE-2026-49453
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Joplin versions prior to 3.6.15
Joplin versions prior to 3.7.2
Description
Joplin accepts synchronized resource metadata where the
id or file extension contains path-separator or parent-directory characters. The BaseItem.unserialize() function stores these unvalidated fields, which are then concatenated into a destination path by resourceFilename(). Consequently, ResourceFetcher writes attacker-controlled resource blobs outside the intended resource directory during background synchronization. An attacker with write access to a shared notebook or a configured sync target can create or overwrite files at an arbitrary path without user interaction.Recommendations
Update to version 3.6.15.
Update to version 3.7.2.
Exploit
Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Joplin