Vulnerabilities
Vulnerable Software
Joplinapp:  >> Joplin  >> 2.8.8  Security Vulnerabilities
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7.
CVSS Score
8.2
EPSS Score
0.002
Published
2026-05-18
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.
CVSS Score
7.8
EPSS Score
0.005
Published
2022-09-30
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CVSS Score
9.0
EPSS Score
0.021
Published
2022-07-25


Contact Us

Shodan ® - All rights reserved