CVE-2024-53268

HIGH

Joplin < 3.0.3 - Remote Code Execution via Unfiltered URI Scheme Handling

Title source: llm
STIX 2.1

Description

Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without any filtering of URI schemes to obtain remote code execution in Windows environments. This issue has been addressed in version 3.0.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0075
EPSS Percentile 50.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
joplin_project/joplin < 3.0.3
Published Nov 25, 2024
Tracked Since Feb 18, 2026