VYPR
Unrated severityNVD Advisory· Published Apr 30, 2025· Updated Apr 30, 2025

Privilege escalation in Joplin server via user patch endpoint

CVE-2025-27134

Description

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint PATCH /api/users/:id to set the is_admin field to 1. The vulnerability allows malicious low-privileged users to perform administrative actions without proper authorization. This issue has been patched in version 3.3.3.

Affected products

2
  • Joplin/Joplinllm-fuzzy
    Range: <3.3.3
  • laurent22/joplinv5
    Range: < 3.3.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.