PatchSiren

laurent22 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM laurent22 CVE published 2026-09-21

CVE-2026-46650

A low-privileged user can publish a crafted HTML note containing a javascript: URL, which can be executed when a victim views the note in an older or non-hardened browser, allowing the script to run in the Joplin Server origin and access page-visible content and make authenticated same-origin requests. The vulnerability affects Joplin Server deployments, particularly those with public shares or exposed to [truncated]

LOW laurent22 CVE published 2026-09-21

CVE-2026-49449

A vulnerability in Joplin, a note-taking and to-do application, allows an attacker to disclose the current user's NTLMv2 challenge-response on Windows. This issue, fixed in version 3.7.2, arises from the application's handling of KaTeX links in note content, enabling an attacker to place a href URL into rendered output without passing Joplin's normal URL allowlist. On Windows, clicking a link whose target [truncated]

CRITICAL laurent22 CVE published 2026-09-21

CVE-2026-46649

CVE-2026-46649 is a critical vulnerability in Joplin Server's GET /api/login_with_code/:id endpoint. This endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce, allowing unlimited guesses by an unauthenticated attacker. A correct code returns a full session token, permitting access to and modification of the user's notes, notebooks, and ac [truncated]

MEDIUM laurent22 CVE published 2026-05-19

CVE-2026-34600

CVE-2026-34600 is a medium-severity information-disclosure issue in Joplin’s delta API. In affected versions 3.5.2 and earlier, share recipients could receive delta output that included the latest state of notes even after those notes were no longer shared with them. The issue is tied to how item state is attached during delta generation and how page-based change compression can incorrectly collapse a cre [truncated]

MEDIUM laurent22 CVE published 2026-05-19

CVE-2025-57798

CVE-2025-57798 is a denial-of-service issue in Joplin’s note title input handling. In versions 3.6.14 and earlier, an excessively long title can trigger out-of-memory conditions and terminate the application. The issue can be reached through the UI by a local user, or through Joplin’s local web service API if an attacker has a valid authentication token. The fix is included in Joplin 3.7.1.

HIGH laurent22 CVE published 2026-05-18

CVE-2026-22810

A path traversal vulnerability in Joplin's OneNote importer allows arbitrary file overwrite via malicious .one attachments. The embedded_file.rs converter fails to sanitize filename paths, enabling directory traversal sequences (../../) to escape intended extraction directories. Attackers can craft malicious OneNote files to overwrite critical system files when imported.