CyberRota Analysis
AI-GeneratedJoplin versions prior to 3.6.15 and 3.7.2 are vulnerable to a path traversal flaw that allows an attacker with write access to a sync target or shared notebook to create or overwrite files at arbitrary locations on the file system during background synchronization. This could lead to unauthorized file manipulation without user interaction, posing a significant risk to data integrity and confidentiality. Users and administrators of Joplin should prioritize upgrading to the patched versions to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or path-separator characters. BaseItem.unserialize() stores the unvalidated fields, resourceFilename() concatenates them into a destination path, and ResourceFetcher writes the attacker-controlled resource blob outside the resource directory during background synchronization. An attacker with write access to a configured sync target or shared notebook can create or overwrite files at an attacker-chosen existing path without user interaction. This issue is fixed in versions 3.6.15 and 3.7.2.