Executive brief
Joplin is a popular privacy-focused note-taking application used across multiple platforms. A vulnerability in versions before 2.11.5 allows attackers to inject malicious JavaScript code through crafted notebook content using HTML area tags, potentially compromising user data or session security. This affects users who open notebooks from untrusted sources. The issue has been fixed in version 2.11.5 and later.
Technical details
The vulnerability is a Cross-site Scripting (CWE-79) flaw in Joplin's HTML rendering engine. The root cause is insufficient sanitization of HTML attributes, specifically within area elements that are part of image map markup. An attacker can create a malicious notebook with a crafted area tag containing XSS payload (e.g., in event handlers or javascript: URLs) that executes when the notebook is rendered. This requires the victim to open the malicious notebook, but no other authentication or network preconditions are needed. Successful exploitation allows arbitrary JavaScript execution in the context of the Joplin application, potentially enabling session hijacking, data theft, or further compromise. The fix was implemented in version 2.11.5 by sanitizing certain HTML attributes and disabling SVG tag support to prevent XSS vectors.
Affected products
- Laurent22 Joplin < 2.11.5
Timeline
- 2023-06-30: disclosed
- 2023-05-28: patched: Version 2.11.5 released with fix