Cross-Site Request Forgery Vulnerability in Joplin by Laurent22
CVE-2026-105785

4.8MEDIUM

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105785?

Joplin is an open-source note-taking and to-do application that has a vulnerability where CSRF, account-confirmation, email-change, and password-reset tokens are not securely managed. This flaw in Joplin Server prior to version 3.7.2 allows an attacker to exploit exposed tokens to force a password reset for a victim. By submitting a valid token to the public password-reset endpoint, the attacker can replace the victim's password, leading to compromised accounts and loss of access to existing sessions and API applications. The issue was addressed in Joplin Server 3.7.2, highlighting the importance of secure token handling.

Affected Version(s)

joplin < 3.7.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.