Executive brief
Joplin Desktop for Windows failed to verify the publisher signature of application updates, allowing an attacker who intercepts the update stream to replace legitimate updates with malicious installers. When users approve the installation, the attacker's code runs with full user privileges, potentially stealing notes, passwords, and other sensitive data stored by the application.
Technical details
The vulnerability stems from a missing publisherName field in the electron-builder Windows configuration, causing NsisUpdater.verifySignature() to skip Authenticode signature validation against Joplin's expected certificate. An attacker with network access to the update delivery path can substitute unsigned or differently-signed installers. The fix adds the publisherName declaration to enforce signature verification on the client side.
Affected products
- Joplin Desktop prior to 3.7.2
Timeline
- 2026-09-21: disclosed: CVE-2026-49450 published
- 2026-05-27: patched: Fix merged in version 3.7.2