CVE-2026-105785
Deferred Deferred - Pending Action

Password Reset Token Misuse in Joplin Server

Vulnerability report for CVE-2026-105785, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
laurent22 joplin < 3.7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
CWE-620 When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Joplin Server before version 3.7.2 stores tokens like CSRF, account-confirmation, email-change, and password-reset tokens without distinguishing their purpose. This allows any valid token for a user to be used in the password-reset flow, enabling an attacker who obtains a token through another channel to reset the victim's password, delete sessions, and revoke API applications.

Detection Guidance

Check if your Joplin Server version is below 3.7.2. Run: curl -s https://your-joplin-server.com/api/version | grep version. If the version is older than 3.7.2, the system is vulnerable.

Impact Analysis

If an attacker gains access to a victim's CSRF or confirmation token, they can reset the victim's password, lock them out of their account, delete all active sessions, and revoke linked API applications. This results in a full account takeover with no need for additional authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating confidentiality requirements in GDPR and HIPAA. It may result in data breaches, unauthorized modifications, and loss of user control over personal information, potentially leading to non-compliance with data protection regulations.

Mitigation Strategies

Upgrade Joplin Server to version 3.7.2 or later immediately. This addresses the token purpose issue by scoping tokens to their intended use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105785. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart