Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105785— Joplin Server password reset accepts tokens issued for unrelated purposes

Quick assessment

Affected
laurent22 joplin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joplin 是一款开源的笔记和待办事项应用程序,它将笔记和列表组织到笔记本中。在 Joplin Server 3.7.2 之前, 中的 CSRF、账户确认、邮箱修改和密码重置令牌未存储用途信息;同时, 中的 方法允许接受由 返回的任何令牌。攻击者若通过其他信息泄露渠道获取受害者的 CSRF 或确认令牌,便可以将该令牌提交至公共密码重置端点,替换受害者的密码,并导致现有会话和 API 应用程序被删除。此问题已在 Joplin Server 3.7.2 中得到修复。

CVSS 4.8 · Medium

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105785

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joplin Server password reset accepts tokens issued for unrelated purposes
Source: CVE Program / CVE List V5
Vulnerability Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
未经验证的口令修改
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
laurent22 joplin < 3.7.2 -

II. Public POCs for CVE-2026-105785

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105785

请登录查看更多情报信息。

Other References for CVE-2026-105785 (3)

Same Patch Batch · laurent22 · 2026-10-05 · 4 CVEs total

CVE-2026-105786 8.5 HIGH Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation
CVE-2026-105783 8.0 HIGH Joplin Web Clipper pairing allows cross-origin theft of a permanent API token
CVE-2026-105784 4.6 MEDIUM Joplin whiteboard card rendering allows CSS injection into application chrome

IV. Related Vulnerabilities

V. Comments for CVE-2026-105785

No comments yet


Leave a comment