CVE-2026-105783
Deferred Deferred - Pending Action

Joplin Desktop Web Clipper Server Origin Validation Bypass

Vulnerability report for CVE-2026-105783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP or HTTPS origins. The desktop confirmation dialog does not identify the requesting origin, so a victim who approves the generic prompt authorizes the attacking page, which then receives the permanent API token. The token provides ongoing read and write access to notes, folders, tags, resources, and master keys. This issue is fixed in version 3.7.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
laurent22 joplin < 3.7.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105783 is a vulnerability in Joplin Desktop's Web Clipper server where the pairing endpoints (/auth and /auth/check) accept requests from any website due to a permissive CORS policy. This allows malicious sites to initiate pairing and steal the user's permanent API token via a generic confirmation dialog.

Detection Guidance

Check if Joplin Desktop is running with the Web Clipper server enabled by inspecting running processes or service logs. Look for unauthorized POST requests to /auth or GET requests to /auth/check endpoints on localhost ports used by Joplin. Verify if the server responds with Access-Control-Allow-Origin: * and lacks Origin/Referer validation.

Impact Analysis

If exploited, an attacker could gain full read/write access to your notes, folders, tags, resources, and master keys. The attack requires visiting a malicious website while the Web Clipper server is enabled. The token provides ongoing access even after the initial compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing personal or confidential information stored in Joplin notes.

Mitigation Strategies

Upgrade Joplin Desktop to version 3.7.13 or later to apply the security fix. Disable the Web Clipper server if not needed. Ensure no unauthorized pairing requests are approved by reviewing recent authorization prompts in Joplin.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart