CyberRota Analysis
AI-GeneratedThe vulnerability affects Joplin Desktop versions prior to 3.7.13, specifically when the opt-in Web Clipper server is enabled, allowing arbitrary websites to exploit the lack of origin validation on critical authentication endpoints. This can lead to unauthorized access to sensitive user data, including notes and API tokens, if a victim inadvertently approves a malicious request. Users and organizations utilizing Joplin for note-taking should prioritize upgrading to version 3.7.13 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP or HTTPS origins. The desktop confirmation dialog does not identify the requesting origin, so a victim who approves the generic prompt authorizes the attacking page, which then receives the permanent API token. The token provides ongoing read and write access to notes, folders, tags, resources, and master keys. This issue is fixed in version 3.7.13.