Path Traversal Vulnerability in Joplin Note-taking Application
CVE-2026-49453
7HIGH
What is CVE-2026-49453?
Joplin, an open-source note-taking and to-do application, has a vulnerability that allows for path traversal due to improper validation of synchronized resource metadata. Specifically, prior to versions 3.6.15 and 3.7.2, the application fails to check the 'id' or 'file_extension' fields for directory traversal characters. This oversight enables an attacker with write access to a configured sync target or a shared notebook to create or overwrite files at arbitrary locations within the file system without user interaction. The issue has been addressed in the latest versions, reinforcing the need for users to update their installations to maintain secure operations.
Affected Version(s)
joplin < 3.6.15 < 3.6.15
joplin >= 3.7.0, < 3.7.2 < 3.7.0, 3.7.2
