Junglewise Threat Intelligence

CVE-2026-59814: Joplin Server stored XSS in resource sharing via empty title

CVE-2026-59814 · Severity: high · CVSS 7.6 · Published 2026-09-21

Technologies: Joplin Server. Vendors: Joplin.

Executive brief

Joplin Server is an open-source note-taking application. A low-privileged user can upload an image file with an empty title and malicious script, then share it publicly. When a victim opens the shared note, the attacker's script executes in the victim's browser with access to sensitive data and the ability to perform actions on their behalf, including reading administrative information.

Technical details

The GET /shares/:id?resource_id= endpoint serves user-uploaded resources with an attacker-controlled MIME type and omits Content-Disposition headers when the resource title is empty, enabling stored XSS. An attacker can craft an SVG file (image/svg+xml) with embedded script and empty title; when rendered inline without proper headers and CSP, the script executes in the Joplin Server origin, allowing access to same-origin data and authenticated user sessions. The fix restricts inline MIME types to a whitelist (images, audio, video, PDF), forces other types to application/octet-stream with attachment disposition, and adds X-Content-Type-Options: nosniff and strict CSP headers.

Affected products

  • Joplin Server prior to 3.7.7

Timeline

  • 2026-09-21: disclosed
  • 2026-06-28: patched: Fix merged in commit 920cd8f

References

Related threats