PT-2026-82680 · Trilium · Trilium
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Trilium versions prior to 0.104.0
Description
The Safe import filter fails to sanitize note titles. The GeoMap note view interpolates a marker note title into raw HTML rendered as innerHTML, which allows an attacker-supplied import archive to inject scripts that execute when the map is displayed. Since the filter does not escape titles, an HTML event-handler payload can survive the import process. On the desktop client, the Electron renderer operates with Node integration enabled, allowing the injected JavaScript to escalate from cross-site scripting to remote code execution on the victim's machine.
Recommendations
Update to version 0.104.0.
Exploit
Fix
RCE
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trilium