Path Traversal Vulnerability in Joplin Note-taking Application
CVE-2026-49453

7HIGH

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-49453?

Joplin, an open-source note-taking and to-do application, has a vulnerability that allows for path traversal due to improper validation of synchronized resource metadata. Specifically, prior to versions 3.6.15 and 3.7.2, the application fails to check the 'id' or 'file_extension' fields for directory traversal characters. This oversight enables an attacker with write access to a configured sync target or a shared notebook to create or overwrite files at arbitrary locations within the file system without user interaction. The issue has been addressed in the latest versions, reinforcing the need for users to update their installations to maintain secure operations.

Affected Version(s)

joplin < 3.6.15 < 3.6.15

joplin >= 3.7.0, < 3.7.2 < 3.7.0, 3.7.2

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.