Executive brief
Joplin, an open-source note-taking application, contains a cross-site scripting (XSS) vulnerability in its HTML note rendering that allows malicious scripts to execute in a victim's browser. An attacker can create a specially crafted note with a javascript: link that bypasses URL validation and, when shared publicly on Joplin Server, can be triggered to steal data or perform actions on behalf of signed-in users. Exploitation requires user interaction (middle-click or "Open in new tab") and succeeds primarily in older browsers, though current Chrome and Firefox block the attack vector.
Technical details
The vulnerability exists in the isAcceptedUrl() function in packages/renderer/htmlUtils.ts, which uses an unanchored regular expression to validate internal resource URLs. A javascript: URL containing a matching 32-character path fragment can pass validation and be emitted into HTML notes. When executed, the script runs in the Joplin Server origin and can read page-visible content and make authenticated same-origin requests if the victim is signed in. The fix tightens the sanitizer to ensure only legitimate internal links match the resource-URL format.
Affected products
- Joplin Joplin prior to 3.7.2
Timeline
- 2026-09-21: disclosed
- 2026-05-15: patched