{"id":"CVE-2026-59815","published":"2026-09-21T22:16:57.207","lastModified":"2026-09-21T22:16:57.207","description":"Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists for the caller, without requiring ShareUserStatus.Accepted. A low-privileged authenticated user with a pending folder-share invitation can create an item under the share ID, and ShareModel.updateSharedItems3() propagates the injected content to the owner and accepted participants before the attacker accepts the invitation. This issue is fixed in version 3.7.7.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/laurent22/joplin/commit/dff533ccbd2b300eac218a11a7619280865e2e9b","tags":[]},{"url":"https://github.com/laurent22/joplin/security/advisories/GHSA-qq59-gg3w-pf7v","tags":[]}],"exploitRefs":[{"url":"https://github.com/laurent22/joplin/commit/dff533ccbd2b300eac218a11a7619280865e2e9b","tags":[]},{"url":"https://github.com/laurent22/joplin/security/advisories/GHSA-qq59-gg3w-pf7v","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a low-privileged authenticated user to create items under a share ID before acceptance, potentially injecting content into shared folders without proper authorization.","exploitability":"Exploitation requires a pending folder-share invitation and access to the Joplin Server. It is moderately difficult due to the need for initial authentication and a specific timing condition.","blast_radius":"If exploited, this could lead to unauthorized content injection into shared folders, impacting multiple users including owners and accepted participants.","remediation":"Update to Joplin version 3.7.7 or later to mitigate the vulnerability.","tags":["auth-bypass","web","note-taking","share-vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:34:11.231Z"}}