Impact
The vulnerability allows a malicious Fountain code block to be injected into a Joplin note, and when Fountain rendering is enabled the generated HTML is included in the note output without sanitization, enabling the script to run in the note viewer. This script execution can read content that subsequently loads in the reused viewer or, when published notes are served from the same domain as the Joplin Server, access data available to an authenticated browser, effectively compromising confidentiality of data stored by the server.
Affected Systems
Joplin applications from vendor laurent22, specifically all releases prior to version 3.6.15 for the 3.6 branch and prior to 3.7.2 for the 3.7 branch, are affected. The issue applies to desktop, mobile clients, and the Joplin Server when publishing notes with Fountain rendering enabled by default.
Risk and Exploitability
The CVSS score of 7.7 indicates a medium to high severity. The EPSS score is not available, and the vulnerability is not in CISA KEV, but the ability to execute arbitrary script in the context of the note viewer or the server origin provides a viable attack vector for an attacker who can manipulate note content or exploit a published note. The vulnerability is primarily exploitable by users who can edit or publish notes, and by downstream consumers of published notes if rendering remains enabled.
OpenCVE Enrichment