CVE-2026-55179
Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from an attacker-supplied internal server ID without checking whether the signed-in user owns or can access that item. Any authenticated user who obtains or guesses another user's item ID can read the corresponding note or item content when end-to-end encryption does not protect it. This issue is fixed in version 3.7.2.
| CWE | CWE-639 |
| Vendor | laurent22 |
| Product | joplin |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for laurent22 joplin
Be the first to know when new medium vulnerabilities affecting laurent22 joplin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
laurent22 / joplin
< 3.7.2