CVE-2026-105783

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,0
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP or HTTPS origins. The desktop confirmation dialog does not identify the requesting origin, so a victim who approves the generic prompt authorizes the attacking page, which then receives the permanent API token. The token provides ongoing read and write access to notes, folders, tags, resources, and master keys. This issue is fixed in version 3.7.13.

346

Origin Validation Error

Draft
Common Consequences
Security Scopes Affected:
Access Control Other
Potential Impacts:
Gain Privileges Or Assume Identity Varies By Context
Applicable Platforms
Technologies: Not Technology-Specific, Web Based
View CWE Details
352

Cross-Site Request Forgery (CSRF)

Stable
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability Non-Repudiation Access Control
Potential Impacts:
Gain Privileges Or Assume Identity Bypass Protection Mechanism Read Application Data Modify Application Data Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
https://github.com/laurent22/joplin/commit/27ae5c0d404ee47ad24862cce917dda6eb29…
https://github.com/laurent22/joplin/pull/16276
https://github.com/laurent22/joplin/releases/tag/v3.7.13
https://github.com/laurent22/joplin/security/advisories/GHSA-9728-v7ww-mxjv