Joplin Remote Code Execution Vulnerability Affects Untrusted PDF Links
CVE-2023-45673

9CRITICAL

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
21 June 2024

What is CVE-2023-45673?

A remote code execution vulnerability has been identified in Joplin, an open-source note-taking application. This flaw allows attackers to execute arbitrary shell commands when a user clicks on a link contained within an untrusted PDF note. The vulnerability arises due to improper handling of top redirection in note viewer iframes and the enabled node integration feature, posing significant risks to users attaching untrusted PDFs. This important security issue has been resolved in version 2.13.3, and users are strongly urged to upgrade to the latest version. As of now, there are no known workarounds to mitigate the risks associated with this vulnerability.

Affected Version(s)

joplin < 2.13.3

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.