Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gcmj-c9gg-9vh6 | @joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files |
Tue, 02 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Msiemens
Msiemens one2html |
|
| CPEs | cpe:2.3:a:msiemens:one2html:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Msiemens
Msiemens one2html |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joplinapp
Joplinapp joplin |
|
| CPEs | cpe:2.3:a:joplinapp:joplin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joplinapp
Joplinapp joplin |
Tue, 19 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laurent 22
Laurent 22 joplin |
|
| Vendors & Products |
Laurent 22
Laurent 22 joplin |
Mon, 18 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7. | |
| Title | Joplin: Path traversal in OneNote importer allows overwriting arbitrary files | |
| Weaknesses | CWE-24 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-20T03:55:23.355Z
Reserved: 2026-01-09T22:50:10.288Z
Link: CVE-2026-22810
Updated: 2026-05-19T12:49:29.457Z
Status : Analyzed
Published: 2026-05-18T21:16:39.373
Modified: 2026-06-17T10:20:28.240
Link: CVE-2026-22810
No data.
OpenCVE Enrichment
Updated: 2026-05-19T08:15:26Z
Github GHSA