PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-57798 laurent22 CVE debrief

CVE-2025-57798 is a denial-of-service issue in Joplin’s note title input handling. In versions 3.6.14 and earlier, an excessively long title can trigger out-of-memory conditions and terminate the application. The issue can be reached through the UI by a local user, or through Joplin’s local web service API if an attacker has a valid authentication token. The fix is included in Joplin 3.7.1.

Vendor
laurent22
Product
joplin
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-07-24
Advisory published
2026-05-19
Advisory updated
2026-07-24

Who should care

Joplin users and administrators running version 3.6.14 or earlier should care, especially on endpoints where local users, malware, or stolen local API tokens are realistic threats. Because the impact is service termination rather than data corruption, this is most relevant for availability-sensitive desktop deployments.

Technical summary

The advisory describes a lack of proper length validation in title input processing. Supplying an excessively long string to the note title field can cause unbounded memory allocation, leading to an out-of-memory error and program termination. The NVD metadata classifies the issue as local, low-complexity, low-privilege, no-user-interaction, with high availability impact and no confidentiality or integrity impact (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The source corpus also maps the weakness to CWE-770.

Defensive priority

Medium. Patch promptly on affected endpoints, but the primary risk is local availability disruption rather than remote compromise.

Recommended defensive actions

  • Upgrade Joplin to version 3.7.1 or later.
  • Review any workflows that expose or store Joplin local web service authentication tokens, and reduce token exposure where possible.
  • Treat the local Joplin API as sensitive on shared or malware-prone endpoints.
  • If running affected versions, avoid pasting untrusted extremely long content into note titles until patched.
  • Use the official GitHub advisory and commit references to confirm the remediation applied in your environment.

Evidence notes

The supplied source corpus states that Joplin versions 3.6.14 and prior are affected and that version 3.7.1 contains the patch. NVD metadata for this CVE lists vulnStatus as Deferred and provides CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with CWE-770 as the associated weakness. The official GitHub advisory and commit are included as references in the source item.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-57798 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-57798

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-57798 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-57798

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.