OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-59814

HIGH · CVSS 7.6 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Joplin Server versions prior to 3.7.7 are vulnerable to a high-severity security flaw that allows low-privileged users to exploit the GET /shares/:id?resource_id= route, enabling them to serve malicious SVG attachments with attacker-controlled MIME types. This vulnerability can lead to cross-site scripting (XSS) attacks, allowing attackers to execute scripts in the context of authenticated users, potentially compromising sensitive data and session tokens. Organizations using Joplin Server should prioritize upgrading to version 3.7.7 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59814
Severity
HIGH
CVSS
7.6
EPSS
0.35%

Original NVD Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and omits Content-Disposition when the resource title is empty. A low-privileged user can publish an empty-title image/svg+xml attachment whose script executes when a victim opens the public share. By default, user content shares the Joplin Server application origin, allowing the script to access same-origin data and, when the victim is authenticated, perform actions with the victim's session, including reading administrative data and anti-CSRF tokens. Installations that configure USER_CONTENT_BASE_URL to a separate origin still execute the script, but on that separate user-content origin rather than the application origin. This issue is fixed in version 3.7.7.