CyberRota Analysis
AI-GeneratedJoplin Server versions prior to 3.7.7 are vulnerable to a high-severity security flaw that allows low-privileged users to exploit the GET /shares/:id?resource_id= route, enabling them to serve malicious SVG attachments with attacker-controlled MIME types. This vulnerability can lead to cross-site scripting (XSS) attacks, allowing attackers to execute scripts in the context of authenticated users, potentially compromising sensitive data and session tokens. Organizations using Joplin Server should prioritize upgrading to version 3.7.7 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and omits Content-Disposition when the resource title is empty. A low-privileged user can publish an empty-title image/svg+xml attachment whose script executes when a victim opens the public share. By default, user content shares the Joplin Server application origin, allowing the script to access same-origin data and, when the victim is authenticated, perform actions with the victim's session, including reading administrative data and anti-CSRF tokens. Installations that configure USER_CONTENT_BASE_URL to a separate origin still execute the script, but on that separate user-content origin rather than the application origin. This issue is fixed in version 3.7.7.