PT-2026-77141 · Unknown · Trilium Notes
CVE-2026-45733
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Trilium Notes versions prior to 0.103.0
Description
Trilium Notes fails to properly encode the
#iconClass label value returned by the getNoteIcon() function. This value is inserted without HTML attribute encoding into class attributes within apps/client/src/widgets/quick search.ts and apps/client/src/services/note autocomplete.ts. This allows a stored payload to execute automatically when a user opens a new tab or uses the Ctrl+J shortcut. Due to the Electron configuration enabling nodeIntegration and disabling contextIsolation, an attacker can execute operating-system commands with the privileges of the victim.Recommendations
Update Trilium Notes to version 0.103.0.
Exploit
Fix
Protection Mechanism Failure
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trilium Notes