CVE-2026-22810

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joplinapp:joplin:*:*:*:*:*:*:*:*
cpe:2.3:a:msiemens:one2html:*:*:*:*:*:rust:*:*

History

02 Jun 2026, 17:04

Type Values Removed Values Added
First Time Msiemens
Msiemens one2html
CPE cpe:2.3:a:msiemens:one2html:*:*:*:*:*:rust:*:*

02 Jun 2026, 16:23

Type Values Removed Values Added
CPE cpe:2.3:a:joplinapp:joplin:*:*:*:*:*:*:*:*
References () https://github.com/laurent22/joplin/blob/af5108d70233b1db9410346958c1587cf7c1b16d/packages/onenote-converter/renderer/src/page/embedded_file.rs#L13-L16 - () https://github.com/laurent22/joplin/blob/af5108d70233b1db9410346958c1587cf7c1b16d/packages/onenote-converter/renderer/src/page/embedded_file.rs#L13-L16 - Product
References () https://github.com/laurent22/joplin/commit/791668455e1aae50501ff57ea4783b3fba9d377c - () https://github.com/laurent22/joplin/commit/791668455e1aae50501ff57ea4783b3fba9d377c - Patch
References () https://github.com/laurent22/joplin/pull/13736 - () https://github.com/laurent22/joplin/pull/13736 - Issue Tracking
References () https://github.com/laurent22/joplin/releases/tag/v3.5.7 - () https://github.com/laurent22/joplin/releases/tag/v3.5.7 - Patch, Product
References () https://github.com/laurent22/joplin/security/advisories/GHSA-gcmj-c9gg-9vh6 - () https://github.com/laurent22/joplin/security/advisories/GHSA-gcmj-c9gg-9vh6 - Vendor Advisory
First Time Joplinapp
Joplinapp joplin

19 May 2026, 14:16

Type Values Removed Values Added
References () https://github.com/laurent22/joplin/security/advisories/GHSA-gcmj-c9gg-9vh6 - () https://github.com/laurent22/joplin/security/advisories/GHSA-gcmj-c9gg-9vh6 -

18 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-18 21:16

Updated : 2026-06-02 17:04


NVD link : CVE-2026-22810

Mitre link : CVE-2026-22810

CVE.ORG link : CVE-2026-22810


JSON object : View

Products Affected

msiemens

  • one2html

joplinapp

  • joplin
CWE
CWE-24

Path Traversal: '../filedir'