CVE-2024-53268 is a high-severity remote code execution vulnerability affecting Joplin, an open-source note-taking application, specifically in Windows environments. Attackers can exploit unfiltered URI schemes within the openExternal function to execute arbitrary code. With a CVSS score of 8.8, this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While there are no known public exploits, Metasploit modules, or active exploitation, users are strongly advised to upgrade to version 3.0.3 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.3CPE matchmatch criteria | cpe:2.3:a:joplin_project:joplin:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.