Security Flaw in Joplin Desktop Affects Update Mechanism
CVE-2026-49450
7.1HIGH
What is CVE-2026-49450?
Joplin Desktop is an open source note-taking application that organizes notes into notebooks. A vulnerability exists in versions prior to 3.7.2, where the absence of publisherName in the package.json file allows the update process to bypass signature verification. This flaw enables an attacker controlling the update delivery path to inject malicious update metadata, leading to the installation of potentially harmful software. If successful, this exploitation compromises user data such as notes and credentials, and allows arbitrary code execution with the user's privileges.
Affected Version(s)
joplin < 3.7.2
