๐Ÿ” CVE Alert

CVE-2026-55105

HIGH 7.7

Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer into note output without sanitizing it. A malicious Fountain code block can therefore execute script when Fountain rendering is enabled in desktop or mobile clients, or when a note is published through Joplin Server where Fountain rendering is enabled by default. The script can read content subsequently loaded in the reused note viewer or, when published notes are served from the same domain as server content, access data available to an authenticated browser in the server origin. This issue is fixed in versions 3.6.15 and 3.7.2.

CWE CWE-79
Vendor laurent22
Product joplin
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for laurent22 joplin

Be the first to know when new high vulnerabilities affecting laurent22 joplin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

laurent22 / joplin
< 3.6.15 >= 3.7.0, < 3.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/laurent22/joplin/security/advisories/GHSA-f7q3-3grx-6wg9 github.com: https://github.com/laurent22/joplin/pull/15659 github.com: https://github.com/laurent22/joplin/commit/8e0812de9d79d1f0698bb76a8c5d7e991df9748d