CVE-2022-40277

HIGH

Joplin 2.8.8 - Remote Code Execution via Malicious Markdown Link Schema

Title source: llm
STIX 2.1

Description

Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://fluidattacks.com/advisories/skrillex/
Product x_refsource_misc
https://github.com/laurent22/joplin

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (2)
joplinapp/joplin 2.8.8
npm/joplin 0npm
Published Sep 30, 2022
Tracked Since Feb 18, 2026