๐Ÿ” CVE Alert

CVE-2026-55179

MEDIUM 6.5

Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from an attacker-supplied internal server ID without checking whether the signed-in user owns or can access that item. Any authenticated user who obtains or guesses another user's item ID can read the corresponding note or item content when end-to-end encryption does not protect it. This issue is fixed in version 3.7.2.

CWE CWE-639
Vendor laurent22
Product joplin
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for laurent22 joplin

Be the first to know when new medium vulnerabilities affecting laurent22 joplin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

laurent22 / joplin
< 3.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/laurent22/joplin/security/advisories/GHSA-r865-g55x-3mfc github.com: https://github.com/laurent22/joplin/pull/15657 github.com: https://github.com/laurent22/joplin/commit/63dfa3b5ab47f29129348b4cd3a161a2dce6bc0e