Arbitrary JavaScript Execution in Joplin Note Taking Application
CVE-2025-25187
What is CVE-2025-25187?
The Joplin note-taking application is vulnerable to arbitrary JavaScript execution due to improper handling of note titles using React's dangerouslySetInnerHTML. This vulnerability arises from the absence of a restrictive Content-Security-Policy for script sources, along with the enabled nodeIntegration, which facilitates the execution of malicious scripts. Users who receive notes from unverified sources and utilize the search function are particularly at risk. The issue has been resolved in version 3.1.24, and users are recommended to update to this version immediately, as there are currently no workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
joplin < 3.1.24
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
