PT-2026-96281 · Unknown · Joplin Server

CVE-2026-59816

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Joplin versions prior to 3.7.7
Description In Joplin Server instances where TRANSCRIBE ENABLED is set to true, the handlers for the endpoints "/api/transcribe/:id" (GET and POST) pass the decoded id directly into transcription backend URLs. An authenticated user can use URL-encoded slash and parent-directory segments within the id variable, causing the parseSubPath() function to decode a path that escapes the intended "/transcribe/" prefix. This allows the server to proxy requests to other transcription-backend endpoints, which may expose internal administrative, health, or configuration data.
Recommendations Update to version 3.7.7. As a temporary mitigation, set TRANSCRIBE ENABLED to false to disable the affected functionality.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59816
GHSA-R7WP-3494-FWF4

Affected Products

Joplin Server