VDB
Sign up
MEDIUM5.4

GHSA-6r7x-hc8m-985r

Cross-site Scripting in Joplin

Quick fix

GHSA-6r7x-hc8m-985r — joplin: upgrade to the fixed version with the command below.

npm install joplin@1.2.1

Details

Joplin through 1.0.184 allows Arbitrary File Read via Cross-site Scripting (XSS).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 0Fixed in: 1.2.1
Fixnpm install joplin@1.2.1

References