CVE-2026-105785 PUBLISHED

Joplin Server password reset accepts tokens issued for unrelated purposes

Assigner: GitHub_M
Reserved: 05.10.2026 Published: 05.10.2026 Updated: 05.10.2026

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victim's CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victim's password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.8

Product Status

Vendor laurent22
Product joplin
Versions
  • Version < 3.7.2 is affected

References

Problem Types

  • CWE-620: Unverified Password Change CWE
  • CWE-640: Weak Password Recovery Mechanism for Forgotten Password CWE