PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46650 laurent22 CVE debrief

A low-privileged user can publish a crafted HTML note containing a javascript: URL, which can be executed when a victim views the note in an older or non-hardened browser, allowing the script to run in the Joplin Server origin and access page-visible content and make authenticated same-origin requests. The vulnerability affects Joplin Server deployments, particularly those with public shares or exposed to untrusted users. To address this issue, defenders should assess exposure, implement compensating controls, and verify remediation. The CVE record and NVD entry provide details on the vulnerability, but further verification of affected versions and potential impact is required.

Vendor
laurent22
Product
joplin
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-29
Advisory published
2026-09-21
Advisory updated
2026-09-29

Who should care

Joplin Server administrators and users, defenders responsible for assessing and mitigating vulnerabilities in note-taking and to-do applications, and security teams responsible for monitoring and incident response.

Why it matters

A medium-severity vulnerability in Joplin allows a low-privileged user to publish crafted HTML notes that can execute JavaScript in the Joplin Server origin, potentially allowing access to page-visible content and authenticated same-origin requests. Defenders should assess exposure, implement compensating controls, and verify remediation.

  • A low-privileged user can publish crafted HTML notes that can execute JavaScript in the Joplin Server origin
  • The script can run in the Joplin Server origin and access page-visible content
  • The script can make authenticated same-origin requests when the victim is signed in
  • Verification of affected versions and potential impact is required

Technical summary

The isAcceptedUrl() function in packages/renderer/htmlUtils.ts uses an unanchored regular expression, allowing a javascript: URL containing a matching 32-character path fragment to pass validation and be emitted into an HTML note's link. This issue allows a low-privileged user to publish crafted HTML notes that can execute JavaScript in the Joplin Server origin, potentially allowing access to page-visible content and authenticated same-origin requests. The vulnerability is fixed in version 3.7.2, and defenders should assess exposure and implement compensating controls.

Defensive priority

Medium priority for Joplin Server administrators and users to verify and update to version 3.7.2, and for defenders to assess exposure and implement compensating controls.

Recommended defensive actions

  • Verify and update Joplin Server to version 3.7.2 or later
  • Assess exposure and implement compensating controls for older or non-hardened browsers
  • Monitor for suspicious activity and implement additional security measures as needed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, and source references include GitHub commits and pull requests. However, the scope of affected versions and potential impact require further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46650 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46650

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46650 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46650

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.