Junglewise Threat Intelligence

CVE-2026-49453: Joplin path traversal in resource synchronization

CVE-2026-49453 · Severity: high · CVSS 7 · Published 2026-09-21

Technologies: Joplin. Vendors: Joplin.

Executive brief

Joplin is an open-source note-taking application that syncs data across devices. Versions before 3.6.15 and 3.7.2 allow attackers with write access to a sync target or shared notebook to create or overwrite arbitrary files on a user's system during background synchronization, without any user interaction needed.

Technical details

The vulnerability is a path traversal flaw in resource metadata handling. BaseItem.unserialize() fails to validate the id or file_extension fields before passing them to resourceFilename(), which concatenates them into a destination path. ResourceFetcher then writes attacker-controlled resource blobs outside the intended resource directory during sync. An attacker needs write access to the sync target or notebook.

Affected products

  • Joplin Joplin before 3.6.15 and before 3.7.2

Timeline

  • 2026-09-21: disclosed
  • 2026-06-20: patched: Fix merged to reject malformed item IDs and improve resource filename determination

References

Related threats