VDB
Sign up
MEDIUM6.1

GHSA-h6c2-879r-jffh

Joplin Desktop App vulnerable to Cross-site Scripting

Quick fix

GHSA-h6c2-879r-jffh — joplin: upgrade to the fixed version with the command below.

npm install joplin@2.9.17

Details

Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 0Fixed in: 2.9.17
Fixnpm install joplin@2.9.17

References