PT-2026-82680 · Trilium · Trilium

·

CVE-2026-48996

·

Published

2026-08-27

·

Updated

2026-08-29

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Trilium versions prior to 0.104.0
Description The Safe import filter fails to sanitize note titles. The GeoMap note view interpolates a marker note title into raw HTML rendered as innerHTML, which allows an attacker-supplied import archive to inject scripts that execute when the map is displayed. Since the filter does not escape titles, an HTML event-handler payload can survive the import process. On the desktop client, the Electron renderer operates with Node integration enabled, allowing the injected JavaScript to escalate from cross-site scripting to remote code execution on the victim's machine.
Recommendations Update to version 0.104.0.

Exploit

Fix

RCE

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48996
GHSA-7QFW-C9GJ-2XQ2

Affected Products

Trilium