Vulnerabilities/

Remote Code Execution on click of <a> Link in markdown preview

Severity:
High

Description

There is a vulnerability in Joplin-desktop that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid.

Recommendation

Update the joplin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
joplin
Anything's wrong? Let us know Last updated on January 30, 2025

This issue is available in SmartScanner Professional

See Pricing