Path traversal in Joplin Server - CVE-2025-27409
Published: April 30, 2025 / Updated: May 26, 2026
Joplin Server
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the findLocalFile function in the default route when handling static file paths beginning with css/pluginAssets or js/pluginAssets. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can be exploited to read files outside the intended directories.