Remote Code Execution Vulnerability in Joplin Note-Taking Application
CVE-2026-55105

7.7HIGH

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-55105?

A security vulnerability in the Joplin note-taking application was identified, where HTML generated by a third-party renderer was not properly sanitized. This could allow malicious Fountain code blocks to execute arbitrary scripts within desktop or mobile clients. When Fountain rendering is enabled, a crafted note can lead to unauthorized access to sensitive data, especially when notes are published via Joplin Server. The issue has been addressed in versions 3.6.15 and 3.7.2, which now include proper input sanitization measures.

Affected Version(s)

joplin < 3.6.15 < 3.6.15

joplin >= 3.7.0, < 3.7.2 < 3.7.0, 3.7.2

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.