VDB
Sign up
CRITICAL9.0

GHSA-ww2v-frv5-pj5x

Joplin is vulnerable to arbitrary code execution

Quick fix

GHSA-ww2v-frv5-pj5x — joplin: upgrade to the fixed version with the command below.

npm install joplin@2.9.1

Details

Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 0Fixed in: 2.9.1
Fixnpm install joplin@2.9.1

References