PT-2026-96279 · Unknown · Joplin Server
CVE-2026-59814
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Joplin Server versions prior to 3.7.7
Description
An issue exists where the 'GET /shares/:id?resource id=' endpoint serves resources with an attacker-controlled mime value and omits the Content-Disposition header when the resource title is empty. A low-privileged user can upload an image/svg+xml attachment with an empty title containing a script that executes when a victim opens the public share. Because user content shares the application origin by default, the script can access same-origin data and perform actions using the victim's session, such as reading administrative data and anti-CSRF tokens. If
USER CONTENT BASE URL is configured to a separate origin, the script still executes but is restricted to that separate user-content origin.Recommendations
Update to version 3.7.7.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joplin Server