PT-2026-96279 · Unknown · Joplin Server

CVE-2026-59814

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joplin Server versions prior to 3.7.7
Description An issue exists where the 'GET /shares/:id?resource id=' endpoint serves resources with an attacker-controlled mime value and omits the Content-Disposition header when the resource title is empty. A low-privileged user can upload an image/svg+xml attachment with an empty title containing a script that executes when a victim opens the public share. Because user content shares the application origin by default, the script can access same-origin data and perform actions using the victim's session, such as reading administrative data and anti-CSRF tokens. If USER CONTENT BASE URL is configured to a separate origin, the script still executes but is restricted to that separate user-content origin.
Recommendations Update to version 3.7.7.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59814
GHSA-MX98-7H4G-6GMH

Affected Products

Joplin Server