PT-2024-35703 · Joplin · Joplin

Luskabol

·

Published

2024-11-25

·

Updated

2025-05-07

·

CVE-2024-53268

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joplin versions prior to 3.0.3
Description The issue allows attackers to abuse the lack of filtering of URI schemes in the openExternal function to obtain remote code execution in Windows environments. There are no known workarounds for this issue.
Recommendations For versions prior to 3.0.3, upgrade to version 3.0.3 or later to address the issue. As a temporary workaround, consider disabling the openExternal function until a patch is available.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-53268
GHSA-PC5V-XP44-5MGV

Affected Products

Joplin