Medium severity4.8NVD Advisory· Published Oct 6, 2026· Updated Oct 6, 2026
CVE-2026-105785
CVE-2026-105785
Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.