CSS Injection Vulnerability in Joplin Note-taking Application
CVE-2026-105784
4.6MEDIUM
What is CVE-2026-105784?
A vulnerability exists in Joplin, an open-source note-taking application, where a specially crafted note containing a jsoncanvas fence can cause security issues. In versions prior to 3.7.13, the whiteboard text and file-node components render content using the full Markdown renderer, allowing a malicious note to inject CSS styles and remote CSS imports. This could lead to unauthorized modifications of the application's user interface, including visual redressing of trusted content. Although inline script execution is blocked by the Content Security Policy, this vulnerability emphasizes the need for vigilance regarding input handling and rendering capabilities. The issue has been resolved in version 3.7.13.
Affected Version(s)
joplin < 3.7.13
