Input validation error in Joplin - CVE-2024-53268
Published: November 25, 2024 / Updated: May 16, 2026
Joplin
Detailed vulnerability description
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation in openExternal in openItem.ts when processing unfiltered URI schemes. A local privileged user can supply a specially crafted URI to execute arbitrary code.
User interaction is required, and the impact occurs in Windows environments.