Cross-site scripting in Joplin Desktop - CVE-2023-38506

 

Cross-site scripting in Joplin Desktop - CVE-2023-38506

Published: June 21, 2024 / Updated: May 16, 2026


Vulnerability identifier: #VU131598
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-38506
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary script code.

The vulnerability exists due to cross-site scripting in the rich text editor when pasting HTML content. A local user can paste crafted HTML to execute arbitrary script code.

User interaction is required to paste the crafted HTML into the editor.


Affected software

Joplin Desktop

How to mitigate CVE-2023-38506

Install security update from vendor's website.

Joplin Desktop - update to 2.12.10

External References

Related Security Bulletins