CVE-2026-49449 | laurent22 Joplin up to 3.7.1 Renderer katex.ts pathExists information disclosure

SecurityVulns

A vulnerability was found in laurent22 Joplin up to 3.7.1. It has been classified as problematic. This affects the function pathExists of the file packages/renderer/MdToHtml/rules/katex.ts of the component Renderer. Performing a manipulation results in information disclosure.

This vulnerability was named CVE-2026-49449. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More