OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-49453

HIGH · CVSS 7 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Joplin versions prior to 3.6.15 and 3.7.2 are vulnerable to a path traversal flaw that allows an attacker with write access to a sync target or shared notebook to create or overwrite files at arbitrary locations on the file system during background synchronization. This could lead to unauthorized file manipulation without user interaction, posing a significant risk to data integrity and confidentiality. Users and administrators of Joplin should prioritize upgrading to the patched versions to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49453
Severity
HIGH
CVSS
7
EPSS
0.41%

Original NVD Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or path-separator characters. BaseItem.unserialize() stores the unvalidated fields, resourceFilename() concatenates them into a destination path, and ResourceFetcher writes the attacker-controlled resource blob outside the resource directory during background synchronization. An attacker with write access to a configured sync target or shared notebook can create or overwrite files at an attacker-chosen existing path without user interaction. This issue is fixed in versions 3.6.15 and 3.7.2.