VDB
Sign up
MEDIUM6.1

GHSA-7grw-xfx6-qhx6

Joplin Cross-site Scripting vulnerability

Quick fix

GHSA-7grw-xfx6-qhx6 — joplin: upgrade to the fixed version with the command below.

npm install joplin@2.11.5

Details

Joplin before 2.11.5 allows XSS via a USE element in an SVG document.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 0Fixed in: 2.11.5
Fixnpm install joplin@2.11.5

References