PatchSiren cyber security CVE debrief
CVE-2025-57798 laurent22 CVE debrief
CVE-2025-57798 is a denial-of-service issue in Joplin’s note title input handling. In versions 3.6.14 and earlier, an excessively long title can trigger out-of-memory conditions and terminate the application. The issue can be reached through the UI by a local user, or through Joplin’s local web service API if an attacker has a valid authentication token. The fix is included in Joplin 3.7.1.
- Vendor
- laurent22
- Product
- joplin
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-24
Who should care
Joplin users and administrators running version 3.6.14 or earlier should care, especially on endpoints where local users, malware, or stolen local API tokens are realistic threats. Because the impact is service termination rather than data corruption, this is most relevant for availability-sensitive desktop deployments.
Technical summary
The advisory describes a lack of proper length validation in title input processing. Supplying an excessively long string to the note title field can cause unbounded memory allocation, leading to an out-of-memory error and program termination. The NVD metadata classifies the issue as local, low-complexity, low-privilege, no-user-interaction, with high availability impact and no confidentiality or integrity impact (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The source corpus also maps the weakness to CWE-770.
Defensive priority
Medium. Patch promptly on affected endpoints, but the primary risk is local availability disruption rather than remote compromise.
Recommended defensive actions
- Upgrade Joplin to version 3.7.1 or later.
- Review any workflows that expose or store Joplin local web service authentication tokens, and reduce token exposure where possible.
- Treat the local Joplin API as sensitive on shared or malware-prone endpoints.
- If running affected versions, avoid pasting untrusted extremely long content into note titles until patched.
- Use the official GitHub advisory and commit references to confirm the remediation applied in your environment.
Evidence notes
The supplied source corpus states that Joplin versions 3.6.14 and prior are affected and that version 3.7.1 contains the patch. NVD metadata for this CVE lists vulnStatus as Deferred and provides CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with CWE-770 as the associated weakness. The official GitHub advisory and commit are included as references in the source item.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-57798 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-57798
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-57798 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-57798
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/laurent22/joplin/commit/5b8795da446a5a40c9e212c98b35e368ffce628e
-
Source reference
Unverified legacy reference
URL: https://github.com/laurent22/joplin/security/advisories/GHSA-6jm8-gr87-q69x
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.