Directory Traversal Vulnerability in Joplin Open Source Note-taking Application
CVE-2026-59816

4.3MEDIUM

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-59816?

A directory traversal vulnerability exists in the Joplin Server versions before 3.7.7. The vulnerability arises when the GET /api/transcribe/:id and POST /api/transcribe/:id endpoints allow an attacker, using an authenticated user account, to craft a job ID that includes URL-encoded characters. This can lead to path traversal, enabling the request to escape the designated /transcribe/ prefix. Consequently, the server may proxy these requests to other transcription-backend endpoints, potentially exposing sensitive internal data, including administrative configuration and health information.

Affected Version(s)

joplin < 3.7.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.