PT-2026-77141 · Unknown · Trilium Notes

CVE-2026-45733

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Trilium Notes versions prior to 0.103.0
Description Trilium Notes fails to properly encode the #iconClass label value returned by the getNoteIcon() function. This value is inserted without HTML attribute encoding into class attributes within apps/client/src/widgets/quick search.ts and apps/client/src/services/note autocomplete.ts. This allows a stored payload to execute automatically when a user opens a new tab or uses the Ctrl+J shortcut. Due to the Electron configuration enabling nodeIntegration and disabling contextIsolation, an attacker can execute operating-system commands with the privileges of the victim.
Recommendations Update Trilium Notes to version 0.103.0.

Exploit

Fix

Protection Mechanism Failure

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45733
GHSA-H45Q-4QC4-8HHG

Affected Products

Trilium Notes