VDB
Sign up
MEDIUM6.1

GHSA-mrmf-755g-w2vw

Joplin vulnerable to Cross-site Scripting in notes

Quick fix

GHSA-mrmf-755g-w2vw — joplin: upgrade to the fixed version with the command below.

npm install joplin@2.0.9

Details

Joplin before 2.0.9 allows Cross-site Scripting via button and form in the note body.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 0Fixed in: 2.0.9
Fixnpm install joplin@2.0.9

References