Junglewise Threat Intelligence

CVE-2021-33295: Joplin Desktop cross-site scripting via NOSCRIPT tags

CVE-2021-33295 · Severity: low · CVSS 3.1 · Published 2022-06-17

Vendors: Joplin.

Executive brief

Joplin is a note-taking and document management application. A cross-site scripting vulnerability in Joplin Desktop allows attackers to execute arbitrary code by embedding malicious NOSCRIPT tags in notes, due to insufficient HTML sanitization. An attacker could use this to steal user data, compromise the user's system, or perform actions on behalf of the user.

Technical details

This is a cross-site scripting (XSS) vulnerability (CWE-79) in Joplin Desktop before version 1.8.5, caused by improper sanitization of HTML content. The vulnerable component is the HTML rendering and sanitization logic in the renderer package (htmlUtils.ts). The attack vector requires user interaction—an attacker must craft a malicious note containing specially-formed NOSCRIPT tags that bypass the HTML sanitizer, which is then opened or displayed by a user. When rendered, the malicious script executes in the context of the application, allowing arbitrary code execution. The vulnerability was patched in version 1.8.5 by filtering out NOSCRIPT tags during HTML sanitization.

Affected products

  • Joplin Joplin Desktop before 1.8.5

Timeline

  • 2022-06-17: disclosed: Advisory published
  • 1.8.5: patched: Vulnerability fixed in Joplin Desktop 1.8.5

References