Security Flaw in Joplin Note-Taking Application Exposes User Credentials
CVE-2026-49449
2.5LOW
What is CVE-2026-49449?
The Joplin note-taking application, from versions 1.4.0 to 3.7.2, has been found to allow malicious URL exposure through the KaTeX rendering feature. This vulnerability arises when users are able to embed unfiltered URLs in their notes, which can lead to the unauthorized disclosure of the user's NTLMv2 challenge-response. The vulnerability is particularly concerning on Windows, where clicking an attacker-controlled UNC path can trigger SMB authentication. As a result, users may inadvertently expose sensitive authentication details without any alerts or warnings. This issue has been addressed in version 3.7.2, underscoring the importance of keeping software updated to mitigate security risks.
Affected Version(s)
joplin >= 1.4.0, < 3.7.2
