Executive brief
Joplin Server is a note-taking application with optional transcription support. When transcription is enabled, authenticated users can exploit URL-encoded path segments to bypass access controls and reach internal transcription backend endpoints, potentially exposing administrative data, health metrics, and configuration information.
Technical details
A path traversal vulnerability in the GET and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts allows authenticated users to inject URL-encoded slashes (%2F) that are decoded after routing, causing the server to construct URLs that escape the intended /transcribe/ prefix. An attacker can craft requests like GET /api/transcribe/..%2Fadmin to proxy requests to arbitrary endpoints on the transcription backend (e.g., /admin or /health), revealing internal data. The vulnerability requires TRANSCRIBE_ENABLED=true (disabled by default) and valid authentication, and is fixed by validating the job ID against an allowlist of safe characters before URL interpolation.
Affected products
- Joplin Joplin Server before 3.7.7
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: fixed in version 3.7.7