Junglewise Threat Intelligence

CVE-2026-59816: Joplin Server path traversal in transcribe proxy

CVE-2026-59816 · Severity: medium · CVSS 4.3 · Published 2026-09-21

Technologies: Joplin Server. Vendors: Joplin.

Executive brief

Joplin Server is a note-taking application with optional transcription support. When transcription is enabled, authenticated users can exploit URL-encoded path segments to bypass access controls and reach internal transcription backend endpoints, potentially exposing administrative data, health metrics, and configuration information.

Technical details

A path traversal vulnerability in the GET and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts allows authenticated users to inject URL-encoded slashes (%2F) that are decoded after routing, causing the server to construct URLs that escape the intended /transcribe/ prefix. An attacker can craft requests like GET /api/transcribe/..%2Fadmin to proxy requests to arbitrary endpoints on the transcription backend (e.g., /admin or /health), revealing internal data. The vulnerability requires TRANSCRIBE_ENABLED=true (disabled by default) and valid authentication, and is fixed by validating the job ID against an allowlist of safe characters before URL interpolation.

Affected products

  • Joplin Joplin Server before 3.7.7

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: fixed in version 3.7.7

References

Related threats