CVE-2026-105784: Joplin whiteboard card rendering allows CSS injection into application chrome
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joplinto a version that resolves this vulnerability.Fixed in 3.7.13
Event History
Frequently Asked Questions
Who is exposed to this issue?
Joplin desktop users running versions earlier than 3.7.13 are exposed when they select a note containing a jsoncanvas fence with malicious whiteboard text or file-node content. Exploitation requires the attacker to get a malicious note opened by a user.
What can an attacker do, and can this lead to code execution?
An attacker can inject CSS, including remote CSS imports, into the application document to alter trusted application chrome, perform UI redressing, signal that a note was opened, and potentially expose attribute values. The documented Content Security Policy blocks inline script execution, so the supported impact does not include code execution.
How can I determine whether I am affected?
Check whether the Joplin desktop version is earlier than 3.7.13 and whether users may open untrusted notes containing jsoncanvas fences. The vulnerable rendering path is triggered when such a note is selected.
What should I do if I cannot update immediately?
Avoid opening or selecting untrusted notes containing jsoncanvas fences, particularly notes received from external or untrusted sources. Updating to version 3.7.13 is the available fix.