{"id":"CVE-2026-49449","published":"2026-09-21T21:17:03.593","lastModified":"2026-09-21T21:17:03.593","description":"Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note author to place a \\href URL into rendered output without passing Joplin's normal URL allowlist. On Windows, clicking a link whose target is an attacker-controlled UNC path causes pathExists() to initiate SMB authentication and disclose the current user's NTLMv2 challenge-response without a warning. The unfiltered URL can also invoke other registered URL handlers, but the credential disclosure through KaTeX \\href is the distinguishing demonstrated impact. This issue is fixed in version 3.7.2.","cvssScore":2.5,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","cwes":["CWE-200","CWE-522","CWE-829"],"vendors":[],"products":[],"references":[{"url":"https://github.com/laurent22/joplin/commit/b15472bc9654a72101b34b79c9436b3d450e2c10","tags":[]},{"url":"https://github.com/laurent22/joplin/pull/15538","tags":[]},{"url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9m2r-pv96-jxr3","tags":[]}],"exploitRefs":[{"url":"https://github.com/laurent22/joplin/commit/b15472bc9654a72101b34b79c9436b3d450e2c10","tags":[]},{"url":"https://github.com/laurent22/joplin/pull/15538","tags":[]},{"url":"https://github.com/laurent22/joplin/security/advisories/GHSA-9m2r-pv96-jxr3","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows unfiltered URLs in notes to disclose NTLMv2 credentials via KaTeX's trust option, enabling attackers to exploit this through SMB authentication.","exploitability":"Exploitation requires a user to click an attacker-controlled link with specific conditions met on Windows.","blast_radius":"If exploited, it could lead to credential disclosure for the current user, impacting local network security.","remediation":"Update Joplin to version 3.7.2 or later to mitigate this vulnerability.","tags":["credential-disclosure","smb-auth","web-app","ntlm"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:37:58.599Z"}}