CVE-2025-24028

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 7, 2025
Updated: Feb 10, 2025
CWE ID 79

Summary

CVE-2025-24028 is a newly discovered cross-site scripting (XSS) vulnerability affecting the Joplin note-taking application. This issue arises due to disparities in how Joplin's HTML sanitizer processes comments compared to web browsers. Consequentially, this vulnerability impacts both the Rich Text Editor and Markdown viewer in Joplin. However, it is important to note that the Markdown viewer, being cross-origin isolated, prevents direct access to the Joplin window's functions or variables by JavaScript. This issue was first identified in commit `9b50539`, and it is not present in version 3.1.24. This XSS vulnerability poses a risk to users who open untrusted notes in the Rich Text Editor. To mitigate this risk, Joplin users are advised to upgrade to version 3.2.12, which addresses this vulnerability. At present, there are no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share