Joplin 是一款开源的笔记与待办事项应用,能够将笔记和列表组织到笔记本中。在版本 3.7.13 之前,当 Joplin 桌面版启用可选的“Web Clipper(网页剪藏)”服务器时,位于 packages/lib/ClipperServer.ts 中的服务器会返回 Access-Control-Allow-Origin: * 响应头,允许任意网站调用 POST /auth 和 GET /auth/check 接口。这是因为配对端点未拒绝来自 HTTP 或 HTTPS 协议的请求来源。 桌面端的确认对话框并未显
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105786 | 8.5 HIGH | Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation |
| CVE-2026-105785 | 4.8 MEDIUM | Joplin Server password reset accepts tokens issued for unrelated purposes |
| CVE-2026-105784 | 4.6 MEDIUM | Joplin whiteboard card rendering allows CSS injection into application chrome |
No comments yet