Description
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
Recommendation
Update the joplin package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.9.1
- Patched version(s): 2.9.1
References
Related Issues
- React Editable Json Tree vulnerable to arbitrary code execution via function parsing - CVE-2022-36010
- Joplin Vulnerable to Code Injection - CVE-2022-23340
- Joplin Remote Code Execution - CVE-2022-40277
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code - CVE-2023-45133
- Tags:
- npm
- joplin
Anything's wrong? Let us know Last updated on January 30, 2023