No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laurent 22
Laurent 22 joplin |
|
| Vendors & Products |
Laurent 22
Laurent 22 joplin |
Tue, 22 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or path-separator characters. BaseItem.unserialize() stores the unvalidated fields, resourceFilename() concatenates them into a destination path, and ResourceFetcher writes the attacker-controlled resource blob outside the resource directory during background synchronization. An attacker with write access to a configured sync target or shared notebook can create or overwrite files at an attacker-chosen existing path without user interaction. This issue is fixed in versions 3.6.15 and 3.7.2. | |
| Title | Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory | |
| Weaknesses | CWE-20 CWE-22 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T13:31:37.953Z
Reserved: 2026-05-30T02:43:33.107Z
Link: CVE-2026-49453
Updated: 2026-09-22T13:31:33.995Z
Status : Received
Published: 2026-09-21T21:17:03.900
Modified: 2026-09-22T14:17:12.937
Link: CVE-2026-49453
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:16:51Z