CVE-2026-105784
Last modified
CVE-2026-105784 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer.
Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/FileNode.tsx to render card content with the full Markdown renderer. The components insert the resulting HTML into the main application document through dangerouslySetInnerHTML. A malicious note can inject style elements and remote CSS imports that modify trusted application chrome, signal when the note is opened, and potentially disclose exposed attribute values. Content Security Policy blocks inline script execution, so the supported impact is CSS injection and UI redressing rather than code execution. This issue is fixed in version 3.7.13.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-105784?
How severe is CVE-2026-105784?
How do I fix CVE-2026-105784?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105773Canimaan Software ClamXAV versions 3.3 - 3.11 contains a loc…7
- CVE-2026-105775A security vulnerability has been detected in vllm-project v…4.3
- CVE-2026-105776A flaw has been found in bhagya3929 Employee-Movement-Tracki…7.3
- CVE-2026-105778A vulnerability has been found in Tenda AC5 02.03.01.111_mul…9.9
- CVE-2026-105782Scrapy is a high-level web crawling and scraping framework f…7.5
- CVE-2026-105783Joplin is an open source note-taking and to-do application t…8
- CVE-2026-105785Joplin is an open source note-taking and to-do application t…4.8
- CVE-2026-105786Joplin is an open source note-taking and to-do application t…8.5
- CVE-2026-105788Microsoft UFO is an open-source framework for intelligent au…8.8
- CVE-2026-105789Microsoft UFO is an open-source framework for intelligent au…5.4
- CVE-2026-10579A flaw was found in Picketlink Federation SAML; the unsolcit…9.8
- CVE-2026-105790Microsoft UFO is an open-source framework for intelligent au…6.4
Are you affected by CVE-2026-105784?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
