A vulnerability, which was classified as problematic , was found in laurent22 joplin up to 3.5.6 . Affected is an unknown function. The manipulation results in path traversal: '../filedir'. This vulnerability is identified as CVE-2026-22810 . The attack is only possible with local access. There is not any exploit available. You should upgrade the affected component.