Security Flaw in Joplin Note-Taking Application Exposes User Credentials
CVE-2026-49449

2.5LOW

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-49449?

The Joplin note-taking application, from versions 1.4.0 to 3.7.2, has been found to allow malicious URL exposure through the KaTeX rendering feature. This vulnerability arises when users are able to embed unfiltered URLs in their notes, which can lead to the unauthorized disclosure of the user's NTLMv2 challenge-response. The vulnerability is particularly concerning on Windows, where clicking an attacker-controlled UNC path can trigger SMB authentication. As a result, users may inadvertently expose sensitive authentication details without any alerts or warnings. This issue has been addressed in version 3.7.2, underscoring the importance of keeping software updated to mitigate security risks.

Affected Version(s)

joplin >= 1.4.0, < 3.7.2

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.