Executive brief
Joplin Desktop App is a note-taking and organization application used for managing personal and business information. A cross-site scripting (XSS) vulnerability in versions before 2.9.17 allows attackers to execute arbitrary code by crafting specially malicious input that bypasses sanitization, potentially compromising user data and system security.
Technical details
A cross-site scripting (CWE-79) vulnerability exists in Joplin Desktop App's markdown rendering component due to improper sanitization of user-supplied strings. The vulnerability is triggered when a specially crafted string is passed to the renderer, allowing an attacker to inject and execute arbitrary JavaScript code. The attack requires user interaction (e.g., opening a malicious note) and network access is not required. An attacker can execute arbitrary code in the context of the Joplin application, potentially stealing notes, modifying data, or compromising the host system. The vulnerability was fixed in version 2.9.17 via commit a2de167, which improved input sanitization in the MdToHtml renderer.
Affected products
- Joplin Desktop App before 2.9.17
Timeline
- 2023-01-31: disclosed
- 2.9.17: patched