CVE-2026-46650 | laurent22 Joplin up to 3.7.1 URL Validation htmlUtils.ts isAcceptedUrl cross-domain policy
A vulnerability was found in laurent22 Joplin up to 3.7.1 and classified as problematic. This affects the function isAcceptedUrl of the file packages/renderer/htmlUtils.ts of the component URL Validation. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is known as CVE-2026-46650. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More