MEDIUM6.1
GHSA-mrmf-755g-w2vw
Joplin vulnerable to Cross-site Scripting in notes
Quick fix
GHSA-mrmf-755g-w2vw — joplin: upgrade to the fixed version with the command below.
npm install joplin@2.0.9Details
Joplin before 2.0.9 allows Cross-site Scripting via button and form in the note body.
Are you affected?
Enter the version of the package you're using.