Impact
The vulnerability allows a low-privileged authenticated user who has a pending folder‑share invitation to create new items under the share identifier. The server authorizes such writes without checking that the share user’s status is "Accepted", so the injected content is immediately propagated to the owner and any other accepted participants. This results in an unauthorized insertion of data into a shared notebook, potentially bypassing the owner’s intent and compromising data integrity.
Affected Systems
Joplin Server versions prior to 3.7.7, developed by laurent22.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale exploits are known. Exploitation requires the attacker to possess a valid authenticated account and a pending share invitation; the attack cannot be performed remotely without such prior access. An attacker can therefore inject arbitrary items into shared notebooks before the owner or other participants are even aware of the invitation.
OpenCVE Enrichment