CVE-2026-105784
Deferred Deferred - Pending Action

Joplin Note-Taking App CSS Injection Vulnerability

Vulnerability report for CVE-2026-105784, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
laurent22 joplin < 3.7.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Joplin (CVE-2026-105784) involves a flaw where whiteboard note content is rendered into the main application document instead of an isolated iframe. This allows malicious notes to inject style elements and remote CSS imports, which can modify the application's interface, signal when the note is opened, and potentially disclose exposed attribute values. The issue occurs because the application uses dangerouslySetInnerHTML to insert rendered HTML, bypassing origin isolation.

Detection Guidance

To detect this vulnerability, check if your Joplin desktop application version is below 3.7.13. Run the command: joplin --version. If the version is older than 3.7.13, the system is vulnerable. Inspect notes containing jsoncanvas fences for malicious style elements or remote CSS imports in whiteboard cards.

Impact Analysis

An attacker could craft a note that injects CSS to alter the application's appearance, trick users into interacting with fake UI elements, or leak sensitive data through CSS attribute selectors. While script execution is blocked by CSP, the vulnerability enables UI redressing, spoofing, and data leakage when a victim opens the malicious note.

Compliance Impact

This vulnerability could lead to data exposure or unauthorized UI modifications, potentially violating GDPR's data protection principles or HIPAA's security requirements for protected health information. The risk of data leakage through CSS exfiltration channels may require organizations to assess and mitigate this issue to maintain compliance.

Mitigation Strategies

Update Joplin to version 3.7.13 or later to apply the security fix that strips unsafe style elements from whiteboard card content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105784. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart