Executive brief
Joplin is a popular note-taking application available on desktop and mobile platforms. A cross-site scripting (XSS) vulnerability in versions before 2.11.5 allows attackers to inject malicious scripts through specially crafted SVG documents, potentially compromising the confidentiality and integrity of user notes when opened in the editor.
Technical details
The vulnerability is a DOM-based cross-site scripting (CWE-79) flaw that allows XSS through the USE element in SVG documents. The vulnerable component is the SVG tag support in the editor, which fails to properly sanitize or restrict SVG-based markup. The attack vector is network-based and requires user interaction (opening a malicious SVG document). An attacker can execute arbitrary JavaScript in the context of the Joplin application, potentially stealing notes or session data. The vulnerability was patched in version 2.11.5 by disabling SVG tag support in the editor.
Affected products
- Joplin Joplin before 2.11.5
Timeline
- 2023-06-30: disclosed
- 2023-06-30: patched: Version 2.11.5 released