Executive brief
Joplin Server is an open source note-taking application that allows users to share folders with other users. A low-privileged user with a pending (uninvited) folder-share invitation can create notes in the shared folder before accepting the invitation, allowing them to inject content that gets distributed to the folder owner and other legitimate participants. This breaks the intended access control model where users should not gain write access until they accept an invitation.
Technical details
The ItemModel.checkIfAllowed() method authorizes writes to items with a share ID by checking only whether a share_users row exists for the caller, without verifying the ShareUserStatus is Accepted. An authenticated attacker with a pending invitation can create an item referencing the share ID, and ShareModel.updateSharedItems3() will propagate that item to the owner and accepted participants before the attacker accepts the invitation. The fix requires checking that the share_user status is explicitly Accepted before allowing writes.
Affected products
- Laurent Cozic Joplin Server prior to 3.7.7
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in version 3.7.7