Junglewise Threat Intelligence

CVE-2026-55105: Joplin cross-site scripting in Fountain code blocks

CVE-2026-55105 · Severity: high · CVSS 7.7 · Published 2026-09-21

Technologies: Joplin. Vendors: Joplin.

Executive brief

Joplin is an open-source note-taking application available on desktop, mobile, and as a server. Attackers can embed malicious code in Fountain-formatted code blocks that executes when the note is viewed or published, potentially reading note content or accessing server data if the application is authenticated to the same domain.

Technical details

The Fountain renderer in packages/renderer/MdToHtml/rules/fountain.ts outputs HTML without sanitization, allowing arbitrary script execution when Fountain rendering is enabled. Attack vectors include viewing notes in desktop/mobile clients or accessing published notes through Joplin Server where Fountain rendering is enabled by default. An attacker with the ability to create or modify notes can exploit this to read subsequently-loaded content or, in server deployments, access authenticated browser context data.

Affected products

  • Joplin Joplin before 3.6.15 and before 3.7.2

Timeline

  • 2026-09-21: disclosed
  • 2026-06-12: patched: Fix merged in versions 3.6.15 and 3.7.2

References

Related threats