CVE-2026-49450 | laurent22 Joplin up to 3.7.1 Update Verification package.json NsisUpdater.verifySignature publisherName data authenticity
A vulnerability labeled as problematic has been found in laurent22 Joplin up to 3.7.1. This affects the function NsisUpdater.verifySignature of the file packages/app-desktop/package.json of the component Update Verification. Such manipulation of the argument publisherName leads to insufficient verification of data authenticity.
This vulnerability is listed as CVE-2026-49450. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More