Executive brief
Joplin is an open-source note-taking application available on desktop, mobile, and as a server. Attackers can embed malicious code in Fountain-formatted code blocks that executes when the note is viewed or published, potentially reading note content or accessing server data if the application is authenticated to the same domain.
Technical details
The Fountain renderer in packages/renderer/MdToHtml/rules/fountain.ts outputs HTML without sanitization, allowing arbitrary script execution when Fountain rendering is enabled. Attack vectors include viewing notes in desktop/mobile clients or accessing published notes through Joplin Server where Fountain rendering is enabled by default. An attacker with the ability to create or modify notes can exploit this to read subsequently-loaded content or, in server deployments, access authenticated browser context data.
Affected products
- Joplin Joplin before 3.6.15 and before 3.7.2
Timeline
- 2026-09-21: disclosed
- 2026-06-12: patched: Fix merged in versions 3.6.15 and 3.7.2