CVE-2026-105785 | laurent22 Joplin up to 3.7.1 Token Validation UserModel.ts UserModel.resetPassword cross-site request forgery
A vulnerability identified as problematic has been detected in laurent22 Joplin up to 3.7.1. Affected is the function UserModel.resetPassword of the file packages/server/src/models/UserModel.ts of the component Token Validation. This manipulation causes cross-site request forgery.
This vulnerability appears as CVE-2026-105785. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More