CVE-2026-105785
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| laurent22 | joplin | < 3.7.2 | affected |
Weaknesses
- CWE-620: CWE-620: Unverified Password Change
- CWE-640: CWE-640: Weak Password Recovery Mechanism for Forgotten Password
References
- https://github.com/laurent22/joplin/security/advisories/GHSA-8qm8-mp6h-qf35
- https://github.com/laurent22/joplin/pull/16274
- https://github.com/laurent22/joplin/commit/7766eefa11fa006b6a1971da24e0c820cf1d2118
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.