Joplin prior to version 2.7.1 allows remote attackers to execute system commands through malicious code in user search results.
{ "nvd_published_at": "2022-02-08T14:15:00Z", "cwe_ids": [ "CWE-94" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-04-23T17:42:18Z" }