MEDIUM 4.8 NVD
CVE-2026-105785
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/mode
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.
References
- https://github.com/laurent22/joplin/commit/7766eefa11fa006b6a1971da24e0c820cf1d2118
- https://github.com/laurent22/joplin/pull/16274
- https://github.com/laurent22/joplin/security/advisories/GHSA-8qm8-mp6h-qf35
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-10-06 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.