VDB
Sign up
MEDIUM6.1

GHSA-cgc7-mwp4-3ccx

Cross-site Scripting in Joplin

Quick fix

GHSA-cgc7-mwp4-3ccx — joplin: upgrade to the fixed version with the command below.

npm install joplin@1.1.7

Details

An XSS issue in Joplin desktop allows arbitrary code execution via a malicious HTML embed tag.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 1.0.190Fixed in: 1.1.7
Fixnpm install joplin@1.1.7

References