CVE-2026-59816 | Laurent22 Joplin up to 3.7.6 Transcription API transcribe.ts parseSubPath ID path traversal

SecurityVulns

A vulnerability categorized as problematic has been discovered in Laurent22 Joplin up to 3.7.6. This vulnerability affects the function parseSubPath of the file packages/server/src/routes/api/transcribe.ts of the component Transcription API. Such manipulation of the argument ID leads to path traversal.

This vulnerability is referenced as CVE-2026-59816. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More