CVE-2026-46649
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/09/2026
Última modificación:
28/09/2026
Descripción
*** Pendiente de traducción *** Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.
Impacto
Puntuación base 4.0
9.10
Gravedad 4.0
CRÍTICA
Referencias a soluciones, herramientas e información
- https://github.com/laurent22/joplin/commit/fd8c1fb53f98f689e846dc164e39f307f09b684d
- https://github.com/laurent22/joplin/pull/15433
- https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h
- https://github.com/laurent22/joplin/tree/v3.7.2
- https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h


