CVE-2026-105784: Joplin whiteboard card rendering allows CSS injection into application chrome

Published Oct 5, 2026
·
Updated

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.

Affected Software

1 affected component
Joplin Joplin<3.7.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Joplin to a version that resolves this vulnerability.

    Fixed in 3.7.13

Event History

Oct 5, 2026
CVE Published
via MITRE·11:11 PM
Data Sourced
via MITRE·11:11 PM
DescriptionSeverityWeakness
Oct 6, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Joplin desktop users running versions earlier than 3.7.13 are exposed when they select a note containing a jsoncanvas fence with malicious whiteboard text or file-node content. Exploitation requires the attacker to get a malicious note opened by a user.

2

What can an attacker do, and can this lead to code execution?

An attacker can inject CSS, including remote CSS imports, into the application document to alter trusted application chrome, perform UI redressing, signal that a note was opened, and potentially expose attribute values. The documented Content Security Policy blocks inline script execution, so the supported impact does not include code execution.

3

How can I determine whether I am affected?

Check whether the Joplin desktop version is earlier than 3.7.13 and whether users may open untrusted notes containing jsoncanvas fences. The vulnerable rendering path is triggered when such a note is selected.

4

What should I do if I cannot update immediately?

Avoid opening or selecting untrusted notes containing jsoncanvas fences, particularly notes received from external or untrusted sources. Updating to version 3.7.13 is the available fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203