Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laurent 22
Laurent 22 joplin |
|
| Vendors & Products |
Laurent 22
Laurent 22 joplin |
Tue, 22 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and omits Content-Disposition when the resource title is empty. A low-privileged user can publish an empty-title image/svg+xml attachment whose script executes when a victim opens the public share. By default, user content shares the Joplin Server application origin, allowing the script to access same-origin data and, when the victim is authenticated, perform actions with the victim's session, including reading administrative data and anti-CSRF tokens. Installations that configure USER_CONTENT_BASE_URL to a separate origin still execute the script, but on that separate user-content origin rather than the application origin. This issue is fixed in version 3.7.7. | |
| Title | Joplin: Stored XSS via inline-served note attachment on published shares | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T13:29:52.943Z
Reserved: 2026-07-07T15:00:50.978Z
Link: CVE-2026-59814
Updated: 2026-09-22T13:29:48.515Z
Status : Received
Published: 2026-09-21T22:16:57.050
Modified: 2026-09-22T14:17:13.677
Link: CVE-2026-59814
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:16:35Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')