CVE-2022-23340: Code Injection
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
Other sources
Joplin prior to version 2.7.1 allows remote attackers to execute system commands through malicious code in user search results.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23340?
CVE-2022-23340 is a vulnerability in Joplin 2.6.10 that allows remote attackers to execute system commands through malicious code in user search results.
How severe is CVE-2022-23340?
CVE-2022-23340 is classified as a critical vulnerability with a severity score of 9.8.
How does CVE-2022-23340 affect Joplin?
CVE-2022-23340 affects Joplin 2.6.10, allowing remote attackers to execute system commands through malicious code.
Is there a fix for CVE-2022-23340?
At the moment, there is no official fix available for CVE-2022-23340. It is recommended to update to the latest version of Joplin when a patch becomes available.
Where can I find more information about CVE-2022-23340?
You can find more information about CVE-2022-23340 on the GitHub issue page: https://github.com/laurent22/joplin/issues/6004.