๐Ÿ” CVE Alert

CVE-2026-49449

LOW 2.5

Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows

CVSS Score
2.5
EPSS Score
0.0%
EPSS Percentile
0th

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note author to place a \href URL into rendered output without passing Joplin's normal URL allowlist. On Windows, clicking a link whose target is an attacker-controlled UNC path causes pathExists() to initiate SMB authentication and disclose the current user's NTLMv2 challenge-response without a warning. The unfiltered URL can also invoke other registered URL handlers, but the credential disclosure through KaTeX \href is the distinguishing demonstrated impact. This issue is fixed in version 3.7.2.

CWE CWE-200 CWE-522 CWE-829
Vendor laurent22
Product joplin
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for laurent22 joplin

Be the first to know when new low vulnerabilities affecting laurent22 joplin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

laurent22 / joplin
>= 1.4.0, < 3.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/laurent22/joplin/security/advisories/GHSA-9m2r-pv96-jxr3 github.com: https://github.com/laurent22/joplin/pull/15538 github.com: https://github.com/laurent22/joplin/commit/b15472bc9654a72101b34b79c9436b3d450e2c10