CVE-2026-105785 | laurent22 Joplin up to 3.7.1 Token Validation UserModel.ts UserModel.resetPassword cross-site request forgery

SecurityVulns

A vulnerability identified as problematic has been detected in laurent22 Joplin up to 3.7.1. Affected is the function UserModel.resetPassword of the file packages/server/src/models/UserModel.ts of the component Token Validation. This manipulation causes cross-site request forgery.

This vulnerability appears as CVE-2026-105785. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More