CSS Injection Vulnerability in Joplin Note-taking Application
CVE-2026-105784

4.6MEDIUM

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105784?

A vulnerability exists in Joplin, an open-source note-taking application, where a specially crafted note containing a jsoncanvas fence can cause security issues. In versions prior to 3.7.13, the whiteboard text and file-node components render content using the full Markdown renderer, allowing a malicious note to inject CSS styles and remote CSS imports. This could lead to unauthorized modifications of the application's user interface, including visual redressing of trusted content. Although inline script execution is blocked by the Content Security Policy, this vulnerability emphasizes the need for vigilance regarding input handling and rendering capabilities. The issue has been resolved in version 3.7.13.

Affected Version(s)

joplin < 3.7.13

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.