Vulnerabilities/

Joplin is vulnerable to arbitrary code execution

Severity:
High

Description

Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

Recommendation

Update the joplin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
joplin
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing