CVE-2026-105785: LAURENT22 Joplin
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.
Affected products
- LAURENT22 Joplin: before 3.7.2 (fixed in 3.7.2)
Published 2026-10-06. Last modified 2026-10-08.