CRITICAL9.8
GHSA-8478-53pv-jxvm
Joplin Vulnerable to Code Injection
Quick fix
GHSA-8478-53pv-jxvm — joplin: upgrade to the fixed version with the command below.
npm install joplin@2.7.1Details
Joplin prior to version 2.7.1 allows remote attackers to execute system commands through malicious code in user search results.
Are you affected?
Enter the version of the package you're using.