/flatpak/joplin/
Joplin
Open-source note taking
![]()
Joplin desktop. This Flatpak wraps the official Linux DEB with zypak. It is not a vendor-official Flatpak.
Joplin is AGPL-3.0; this Flatpak is a redistribution, not vendor official.

Install
flatpak --user remote-add --if-not-exists thepeoples \
https://flatpak.thepeoples.io/thepeoples.flatpakrepo
flatpak --user install -y thepeoples io.thepeoples.Joplin
flatpak --user install -y thepeoples io.thepeoples.Joplin//3.6.16Optional system install uses sudo flatpak remote-add --if-not-exists --system and sudo flatpak install -y --system. The //version form pins the advertised ostree branch; stable tracks the latest advertised tree.
Previous versions
The remote keeps the current tree plus the last two vendor versions as extra ostree branches for rollback. Objects stay on the remote after a branch is dropped (publish does not delete).
- Version
3.6.15(ostreeaff0dda63d19267bf765577d330630d71a4ab24b6e01bbcbeec7e9f47920203a)
flatpak --user install -y thepeoples io.thepeoples.Joplin//3.6.15Verify
- App id
io.thepeoples.Joplin, vendor Laurent Cozic, version3.6.16, license AGPL-3.0-or-later - Download 157.4 MB · installed 427.0 MB
- sha256
1b7f42d2ee978b1adf5cd95b8880b48769f42e3135076632392192022e300e7d - Ostree key fingerprint
98D786877B6C4E8C6889CBD2E75B1C5B0CB2D841 - Homepage https://joplinapp.org/
Input scan
Pinned deb Joplin-3.6.16.deb, extracted without install scripts, scanned before wrap. 2026-09-02 14:16 UTC · trivy 0.73.0 · vuln DB 2026-09-01.
Wrap
Layers this remote adds. Gate fails on CRITICAL.
none
gate pass
Vendor
In the upstream package. Not patched here.
6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW
Vendor findings 81 · 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW
| Severity | ID | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CRITICAL | CVE-2021-44906 | minimist | 1.2.0 | 1.2.6, 0.2.4 | minimist: prototype pollution |
| CRITICAL | CVE-2021-44906 | minimist | 1.2.3 | 1.2.6, 0.2.4 | minimist: prototype pollution |
| CRITICAL | CVE-2021-44906 | minimist | 1.2.5 | 1.2.6, 0.2.4 | minimist: prototype pollution |
| CRITICAL | CVE-2026-59873 | tar | 6.0.2 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| CRITICAL | CVE-2026-59873 | tar | 6.1.11 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| CRITICAL | CVE-2026-59873 | tar | 6.1.2 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| HIGH | CVE-2026-25547 | @isaacs/brace-expansion | 5.0.0 | 5.0.1 | brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion |
| HIGH | CVE-2026-13149 | brace-expansion | 1.1.7 | 5.0.7, 1.1.16, 2.1.2 | brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity |
| HIGH | CVE-2026-14257 | brace-expansion | 1.1.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function |
| HIGH | CVE-2026-69152 | brace-expansion | 1.1.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| HIGH | CVE-2022-25881 | http-cache-semantics | 4.1.0 | 4.1.1 | http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability |
| HIGH | CVE-2020-7788 | ini | 1.3.0 | 1.3.6 | nodejs-ini: Prototype pollution via malicious INI file |
| HIGH | CVE-2024-29415 | ip | 1.1.5 | — | node-ip: Incomplete fix for CVE-2023-42282 |
| HIGH | CVE-2022-3517 | minimatch | 3.0.4 | 3.0.5 | nodejs-minimatch: ReDoS via the braceExpand function |
| HIGH | CVE-2026-26996 | minimatch | 10.1.1 | 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 | minimatch: minimatch: Denial of Service via specially crafted glob patterns |
| HIGH | CVE-2026-26996 | minimatch | 3.0.4 | 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 | minimatch: minimatch: Denial of Service via specially crafted glob patterns |
| HIGH | CVE-2026-27903 | minimatch | 10.1.1 | 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 | minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns |
| HIGH | CVE-2026-27903 | minimatch | 3.0.4 | 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 | minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns |
| HIGH | CVE-2026-27904 | minimatch | 10.1.1 | 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 | minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions |
| HIGH | CVE-2026-27904 | minimatch | 3.0.4 | 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 | minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions |
| HIGH | CVE-2022-24713 | regex | 1.4.6 | 1.5.5 | Mozilla: Denial of Service via complex regular expressions |
| HIGH | CVE-2022-25883 | semver | 6.0.0 | 7.5.2, 6.3.1, 5.7.2 | nodejs-semver: Regular expression denial of service |
| HIGH | CVE-2022-25883 | semver | 7.3.5 | 7.5.2, 6.3.1, 5.7.2 | nodejs-semver: Regular expression denial of service |
| HIGH | CVE-2022-0355 | simple-get | 4.0.0 | 4.0.1, 3.1.1, 2.8.2 | simple-get: exposure of sensitive information to an unauthorized actor |
| HIGH | CVE-2021-27290 | ssri | 8.0.0 | 6.0.2, 7.1.1, 8.0.1 | nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode |
| HIGH | CVE-2021-32803 | tar | 6.0.2 | 3.2.3, 4.4.15, 5.0.7, 6.1.2 | nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite |
| HIGH | CVE-2021-32804 | tar | 6.0.2 | 3.2.2, 4.4.14, 5.0.6, 6.1.1 | nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite |
| HIGH | CVE-2021-37701 | tar | 6.0.2 | 4.4.16, 5.0.8, 6.1.7 | nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite |
| HIGH | CVE-2021-37701 | tar | 6.1.2 | 4.4.16, 5.0.8, 6.1.7 | nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite |
| HIGH | CVE-2021-37712 | tar | 6.0.2 | 4.4.18, 5.0.10, 6.1.9 | nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite |
| HIGH | CVE-2021-37712 | tar | 6.1.2 | 4.4.18, 5.0.10, 6.1.9 | nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite |
| HIGH | CVE-2021-37713 | tar | 6.0.2 | 4.4.18, 5.0.10, 6.1.9 | nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization |
| HIGH | CVE-2021-37713 | tar | 6.1.2 | 4.4.18, 5.0.10, 6.1.9 | nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization |
| HIGH | CVE-2026-23745 | tar | 6.0.2 | 7.5.3 | node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives |
| HIGH | CVE-2026-23745 | tar | 6.1.11 | 7.5.3 | node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives |
| HIGH | CVE-2026-23745 | tar | 6.1.2 | 7.5.3 | node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives |
| HIGH | CVE-2026-23950 | tar | 6.0.2 | 7.5.4 | node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition |
| HIGH | CVE-2026-23950 | tar | 6.1.11 | 7.5.4 | node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition |
| HIGH | CVE-2026-23950 | tar | 6.1.2 | 7.5.4 | node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition |
| HIGH | CVE-2026-24842 | tar | 6.0.2 | 7.5.7 | node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check |
| HIGH | CVE-2026-24842 | tar | 6.1.11 | 7.5.7 | node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check |
| HIGH | CVE-2026-24842 | tar | 6.1.2 | 7.5.7 | node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check |
| HIGH | CVE-2026-26960 | tar | 6.0.2 | 7.5.8 | node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation |
| HIGH | CVE-2026-26960 | tar | 6.1.11 | 7.5.8 | node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation |
| HIGH | CVE-2026-26960 | tar | 6.1.2 | 7.5.8 | node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation |
| HIGH | CVE-2026-29786 | tar | 6.0.2 | 7.5.10 | node-tar: hardlink path traversal via drive-relative linkpath |
| HIGH | CVE-2026-29786 | tar | 6.1.11 | 7.5.10 | node-tar: hardlink path traversal via drive-relative linkpath |
| HIGH | CVE-2026-29786 | tar | 6.1.2 | 7.5.10 | node-tar: hardlink path traversal via drive-relative linkpath |
| HIGH | CVE-2026-31802 | tar | 6.0.2 | 7.5.11 | tar: tar: File overwrite via drive-relative symlink traversal |
| HIGH | CVE-2026-31802 | tar | 6.1.11 | 7.5.11 | tar: tar: File overwrite via drive-relative symlink traversal |
| HIGH | CVE-2026-31802 | tar | 6.1.2 | 7.5.11 | tar: tar: File overwrite via drive-relative symlink traversal |
| HIGH | CVE-2026-59874 | tar | 6.0.2 | 7.5.18 | tar: Node-tar: Denial of Service via malformed tar archive header |
| HIGH | CVE-2026-59874 | tar | 6.1.11 | 7.5.18 | tar: Node-tar: Denial of Service via malformed tar archive header |
| HIGH | CVE-2026-59874 | tar | 6.1.2 | 7.5.18 | tar: Node-tar: Denial of Service via malformed tar archive header |
| HIGH | CVE-2026-73566 | tar | 6.0.2 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| HIGH | CVE-2026-73566 | tar | 6.1.11 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| HIGH | CVE-2026-73566 | tar | 6.1.2 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| HIGH | CVE-2024-12905 | tar-fs | 2.0.0 | 1.16.4, 2.1.2, 3.0.7 | tar-fs: link following and path traversal via maliciously crafted tar file |
| HIGH | CVE-2025-48387 | tar-fs | 2.0.0 | 1.16.5, 2.1.3, 3.0.9 | tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball |
| HIGH | CVE-2025-59343 | tar-fs | 2.0.0 | 3.1.1, 2.1.4, 1.16.6 | tar-fs: tar-fs symlink validation bypass |
| MEDIUM | CVE-2026-33750 | brace-expansion | 1.1.7 | 5.0.5, 3.0.2, 2.0.3, 1.1.13 | brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern |
| MEDIUM | CVE-2026-25541 | bytes | 1.10.1 | 1.11.1 | Bytes is a utility library for working with bytes. From version 1.2.1 ... |
| MEDIUM | CVE-2020-7598 | minimist | 1.2.0 | 0.2.1, 1.2.3 | nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload |
| MEDIUM | CVE-2024-28863 | tar | 6.0.2 | 6.2.1 | node-tar: denial of service while parsing a tar file due to lack of folders depth validation |
| MEDIUM | CVE-2024-28863 | tar | 6.1.11 | 6.2.1 | node-tar: denial of service while parsing a tar file due to lack of folders depth validation |
| MEDIUM | CVE-2024-28863 | tar | 6.1.2 | 6.2.1 | node-tar: denial of service while parsing a tar file due to lack of folders depth validation |
| MEDIUM | CVE-2026-53655 | tar | 6.0.2 | 7.5.16 | node-tar: node-tar: File smuggling due to inconsistent tar archive parsing |
| MEDIUM | CVE-2026-53655 | tar | 6.1.11 | 7.5.16 | node-tar: node-tar: File smuggling due to inconsistent tar archive parsing |
| MEDIUM | CVE-2026-53655 | tar | 6.1.2 | 7.5.16 | node-tar: node-tar: File smuggling due to inconsistent tar archive parsing |
| MEDIUM | CVE-2026-59871 | tar | 6.0.2 | 7.5.18 | node-tar: node-tar: Denial of Service due to incorrect PAX path handling |
| MEDIUM | CVE-2026-59871 | tar | 6.1.11 | 7.5.18 | node-tar: node-tar: Denial of Service due to incorrect PAX path handling |
| MEDIUM | CVE-2026-59871 | tar | 6.1.2 | 7.5.18 | node-tar: node-tar: Denial of Service due to incorrect PAX path handling |
| MEDIUM | CVE-2026-59875 | tar | 6.0.2 | 7.5.17 | node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
| MEDIUM | CVE-2026-59875 | tar | 6.1.11 | 7.5.17 | node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
| MEDIUM | CVE-2026-59875 | tar | 6.1.2 | 7.5.17 | node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
| MEDIUM | CVE-2026-25727 | time | 0.3.44 | 0.3.47 | time: time affected by a stack exhaustion denial of service attack |
| LOW | CVE-2025-5889 | brace-expansion | 1.1.7 | 2.0.2, 1.1.12, 3.0.1, 4.0.1 | brace-expansion: juliangruber brace-expansion index.js expand redos |
| LOW | CVE-2017-16137 | debug | 4.1.0 | 2.6.9, 3.1.0, 3.2.7, 4.3.1 | nodejs-debug: Regular expression Denial of Service |
| LOW | CVE-2023-42282 | ip | 1.1.5 | 2.0.1, 1.1.9 | nodejs-ip: arbitrary code execution via the isPublic() function |
| LOW | GHSA-cq8v-f236-94qc | rand | 0.7.3 | 0.9.3, 0.10.1, 0.8.6 | Rand is unsound with a custom logger using rand::rng() |
| LOW | CVE-2025-58160 | tracing-subscriber | 0.2.25 | 0.3.20 | tracing-subscriber: Tracing log pollution |
Previous scans
Daily Trivy refresh. Current report plus the last 14 full scans; older copies are deleted.
| Scanned | Vuln DB | Version | Wrap | Vendor | Report |
|---|---|---|---|---|---|
| 2026-09-02 14:02 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-02 06:51 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-02 04:58 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-02 04:31 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-02 03:57 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-02 03:44 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-02 01:42 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-01 07:28 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-09-01 06:51 UTC | 2026-09-01 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-08-31 09:27 UTC | 2026-08-31 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-08-31 07:28 UTC | 2026-08-31 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-08-31 06:50 UTC | 2026-08-31 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-08-30 07:29 UTC | 2026-08-30 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |
| 2026-08-30 06:51 UTC | 2026-08-30 | 3.6.16 | none | 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW | JSON |