CVE-2026-46649
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
28/09/2026
Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.
Impact
Base Score 4.0
9.10
Severity 4.0
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/laurent22/joplin/commit/fd8c1fb53f98f689e846dc164e39f307f09b684d
- https://github.com/laurent22/joplin/pull/15433
- https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h
- https://github.com/laurent22/joplin/tree/v3.7.2
- https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h


