/flatpak/joplin/

Joplin

Open-source note taking

Joplin desktop. This Flatpak wraps the official Linux DEB with zypak. It is not a vendor-official Flatpak.

Joplin is AGPL-3.0; this Flatpak is a redistribution, not vendor official.

notesmarkdownjoplin

Notebooks and editor
Notebooks and editor

Install

flatpak --user remote-add --if-not-exists thepeoples \
  https://flatpak.thepeoples.io/thepeoples.flatpakrepo
flatpak --user install -y thepeoples io.thepeoples.Joplin
flatpak --user install -y thepeoples io.thepeoples.Joplin//3.6.16

Optional system install uses sudo flatpak remote-add --if-not-exists --system and sudo flatpak install -y --system. The //version form pins the advertised ostree branch; stable tracks the latest advertised tree.

Previous versions

The remote keeps the current tree plus the last two vendor versions as extra ostree branches for rollback. Objects stay on the remote after a branch is dropped (publish does not delete).

flatpak --user install -y thepeoples io.thepeoples.Joplin//3.6.15

Verify

Input scan

Pinned deb Joplin-3.6.16.deb, extracted without install scripts, scanned before wrap. 2026-09-02 14:16 UTC · trivy 0.73.0 · vuln DB 2026-09-01.

Wrap

Layers this remote adds. Gate fails on CRITICAL.

none

gate pass

Vendor

In the upstream package. Not patched here.

6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW

Vendor findings 81 · 6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOW
SeverityIDPackageInstalledFixedTitle
CRITICALCVE-2021-44906minimist1.2.01.2.6, 0.2.4minimist: prototype pollution
CRITICALCVE-2021-44906minimist1.2.31.2.6, 0.2.4minimist: prototype pollution
CRITICALCVE-2021-44906minimist1.2.51.2.6, 0.2.4minimist: prototype pollution
CRITICALCVE-2026-59873tar6.0.27.5.19tar: node-tar: Denial of Service via crafted gzip bomb
CRITICALCVE-2026-59873tar6.1.117.5.19tar: node-tar: Denial of Service via crafted gzip bomb
CRITICALCVE-2026-59873tar6.1.27.5.19tar: node-tar: Denial of Service via crafted gzip bomb
HIGHCVE-2026-25547@isaacs/brace-expansion5.0.05.0.1brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion
HIGHCVE-2026-13149brace-expansion1.1.75.0.7, 1.1.16, 2.1.2brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
HIGHCVE-2026-14257brace-expansion1.1.75.0.8, 3.0.3, 2.1.3, 1.1.17brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
HIGHCVE-2026-69152brace-expansion1.1.71.1.18, 2.1.4, 3.0.6, 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
HIGHCVE-2022-25881http-cache-semantics4.1.04.1.1http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability
HIGHCVE-2020-7788ini1.3.01.3.6nodejs-ini: Prototype pollution via malicious INI file
HIGHCVE-2024-29415ip1.1.5node-ip: Incomplete fix for CVE-2023-42282
HIGHCVE-2022-3517minimatch3.0.43.0.5nodejs-minimatch: ReDoS via the braceExpand function
HIGHCVE-2026-26996minimatch10.1.110.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3minimatch: minimatch: Denial of Service via specially crafted glob patterns
HIGHCVE-2026-26996minimatch3.0.410.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3minimatch: minimatch: Denial of Service via specially crafted glob patterns
HIGHCVE-2026-27903minimatch10.1.110.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns
HIGHCVE-2026-27903minimatch3.0.410.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns
HIGHCVE-2026-27904minimatch10.1.110.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
HIGHCVE-2026-27904minimatch3.0.410.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
HIGHCVE-2022-24713regex1.4.61.5.5Mozilla: Denial of Service via complex regular expressions
HIGHCVE-2022-25883semver6.0.07.5.2, 6.3.1, 5.7.2nodejs-semver: Regular expression denial of service
HIGHCVE-2022-25883semver7.3.57.5.2, 6.3.1, 5.7.2nodejs-semver: Regular expression denial of service
HIGHCVE-2022-0355simple-get4.0.04.0.1, 3.1.1, 2.8.2simple-get: exposure of sensitive information to an unauthorized actor
HIGHCVE-2021-27290ssri8.0.06.0.2, 7.1.1, 8.0.1nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode
HIGHCVE-2021-32803tar6.0.23.2.3, 4.4.15, 5.0.7, 6.1.2nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite
HIGHCVE-2021-32804tar6.0.23.2.2, 4.4.14, 5.0.6, 6.1.1nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite
HIGHCVE-2021-37701tar6.0.24.4.16, 5.0.8, 6.1.7nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite
HIGHCVE-2021-37701tar6.1.24.4.16, 5.0.8, 6.1.7nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite
HIGHCVE-2021-37712tar6.0.24.4.18, 5.0.10, 6.1.9nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite
HIGHCVE-2021-37712tar6.1.24.4.18, 5.0.10, 6.1.9nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite
HIGHCVE-2021-37713tar6.0.24.4.18, 5.0.10, 6.1.9nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
HIGHCVE-2021-37713tar6.1.24.4.18, 5.0.10, 6.1.9nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
HIGHCVE-2026-23745tar6.0.27.5.3node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives
HIGHCVE-2026-23745tar6.1.117.5.3node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives
HIGHCVE-2026-23745tar6.1.27.5.3node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives
HIGHCVE-2026-23950tar6.0.27.5.4node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition
HIGHCVE-2026-23950tar6.1.117.5.4node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition
HIGHCVE-2026-23950tar6.1.27.5.4node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition
HIGHCVE-2026-24842tar6.0.27.5.7node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check
HIGHCVE-2026-24842tar6.1.117.5.7node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check
HIGHCVE-2026-24842tar6.1.27.5.7node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check
HIGHCVE-2026-26960tar6.0.27.5.8node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation
HIGHCVE-2026-26960tar6.1.117.5.8node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation
HIGHCVE-2026-26960tar6.1.27.5.8node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation
HIGHCVE-2026-29786tar6.0.27.5.10node-tar: hardlink path traversal via drive-relative linkpath
HIGHCVE-2026-29786tar6.1.117.5.10node-tar: hardlink path traversal via drive-relative linkpath
HIGHCVE-2026-29786tar6.1.27.5.10node-tar: hardlink path traversal via drive-relative linkpath
HIGHCVE-2026-31802tar6.0.27.5.11tar: tar: File overwrite via drive-relative symlink traversal
HIGHCVE-2026-31802tar6.1.117.5.11tar: tar: File overwrite via drive-relative symlink traversal
HIGHCVE-2026-31802tar6.1.27.5.11tar: tar: File overwrite via drive-relative symlink traversal
HIGHCVE-2026-59874tar6.0.27.5.18tar: Node-tar: Denial of Service via malformed tar archive header
HIGHCVE-2026-59874tar6.1.117.5.18tar: Node-tar: Denial of Service via malformed tar archive header
HIGHCVE-2026-59874tar6.1.27.5.18tar: Node-tar: Denial of Service via malformed tar archive header
HIGHCVE-2026-73566tar6.0.27.5.21tar: node-tar: Denial of Service via crafted long-path tar archive
HIGHCVE-2026-73566tar6.1.117.5.21tar: node-tar: Denial of Service via crafted long-path tar archive
HIGHCVE-2026-73566tar6.1.27.5.21tar: node-tar: Denial of Service via crafted long-path tar archive
HIGHCVE-2024-12905tar-fs2.0.01.16.4, 2.1.2, 3.0.7tar-fs: link following and path traversal via maliciously crafted tar file
HIGHCVE-2025-48387tar-fs2.0.01.16.5, 2.1.3, 3.0.9tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball
HIGHCVE-2025-59343tar-fs2.0.03.1.1, 2.1.4, 1.16.6tar-fs: tar-fs symlink validation bypass
MEDIUMCVE-2026-33750brace-expansion1.1.75.0.5, 3.0.2, 2.0.3, 1.1.13brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern
MEDIUMCVE-2026-25541bytes1.10.11.11.1Bytes is a utility library for working with bytes. From version 1.2.1 ...
MEDIUMCVE-2020-7598minimist1.2.00.2.1, 1.2.3nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload
MEDIUMCVE-2024-28863tar6.0.26.2.1node-tar: denial of service while parsing a tar file due to lack of folders depth validation
MEDIUMCVE-2024-28863tar6.1.116.2.1node-tar: denial of service while parsing a tar file due to lack of folders depth validation
MEDIUMCVE-2024-28863tar6.1.26.2.1node-tar: denial of service while parsing a tar file due to lack of folders depth validation
MEDIUMCVE-2026-53655tar6.0.27.5.16node-tar: node-tar: File smuggling due to inconsistent tar archive parsing
MEDIUMCVE-2026-53655tar6.1.117.5.16node-tar: node-tar: File smuggling due to inconsistent tar archive parsing
MEDIUMCVE-2026-53655tar6.1.27.5.16node-tar: node-tar: File smuggling due to inconsistent tar archive parsing
MEDIUMCVE-2026-59871tar6.0.27.5.18node-tar: node-tar: Denial of Service due to incorrect PAX path handling
MEDIUMCVE-2026-59871tar6.1.117.5.18node-tar: node-tar: Denial of Service due to incorrect PAX path handling
MEDIUMCVE-2026-59871tar6.1.27.5.18node-tar: node-tar: Denial of Service due to incorrect PAX path handling
MEDIUMCVE-2026-59875tar6.0.27.5.17node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata
MEDIUMCVE-2026-59875tar6.1.117.5.17node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata
MEDIUMCVE-2026-59875tar6.1.27.5.17node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata
MEDIUMCVE-2026-25727time0.3.440.3.47time: time affected by a stack exhaustion denial of service attack
LOWCVE-2025-5889brace-expansion1.1.72.0.2, 1.1.12, 3.0.1, 4.0.1brace-expansion: juliangruber brace-expansion index.js expand redos
LOWCVE-2017-16137debug4.1.02.6.9, 3.1.0, 3.2.7, 4.3.1nodejs-debug: Regular expression Denial of Service
LOWCVE-2023-42282ip1.1.52.0.1, 1.1.9nodejs-ip: arbitrary code execution via the isPublic() function
LOWGHSA-cq8v-f236-94qcrand0.7.30.9.3, 0.10.1, 0.8.6Rand is unsound with a custom logger using rand::rng()
LOWCVE-2025-58160tracing-subscriber0.2.250.3.20tracing-subscriber: Tracing log pollution

Full report (JSON)

Previous scans

Daily Trivy refresh. Current report plus the last 14 full scans; older copies are deleted.

ScannedVuln DBVersionWrapVendorReport
2026-09-02 14:02 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-02 06:51 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-02 04:58 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-02 04:31 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-02 03:57 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-02 03:44 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-02 01:42 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-01 07:28 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-09-01 06:51 UTC2026-09-013.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-08-31 09:27 UTC2026-08-313.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-08-31 07:28 UTC2026-08-313.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-08-31 06:50 UTC2026-08-313.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-08-30 07:29 UTC2026-08-303.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON
2026-08-30 06:51 UTC2026-08-303.6.16none6 CRITICAL · 54 HIGH · 16 MEDIUM · 5 LOWJSON