Executive brief
Joplin is an open-source note-taking application that syncs data across devices. Versions before 3.6.15 and 3.7.2 allow attackers with write access to a sync target or shared notebook to create or overwrite arbitrary files on a user's system during background synchronization, without any user interaction needed.
Technical details
The vulnerability is a path traversal flaw in resource metadata handling. BaseItem.unserialize() fails to validate the id or file_extension fields before passing them to resourceFilename(), which concatenates them into a destination path. ResourceFetcher then writes attacker-controlled resource blobs outside the intended resource directory during sync. An attacker needs write access to the sync target or notebook.
Affected products
- Joplin Joplin before 3.6.15 and before 3.7.2
Timeline
- 2026-09-21: disclosed
- 2026-06-20: patched: Fix merged to reject malformed item IDs and improve resource filename determination