Open Source Note-Taking Application Vulnerability in Joplin by Laurent22
CVE-2026-105783
8HIGH
What is CVE-2026-105783?
Joplin, a popular open-source note-taking and to-do application, harbors a significant vulnerability in its Web Clipper server. When operated with the opt-in feature enabled, the server's response to CORS requests is improperly configured, allowing all websites to gain unauthorized access. This misconfiguration means that malicious sites can exploit the pairing endpoints, leading users to inadvertently authorize these sites to access sensitive API tokens. These tokens grant continuous read and write access to user notes, folders, tags, and more. Users should ensure they update to version 3.7.13 to mitigate this security risk.
Affected Version(s)
joplin < 3.7.13
