PT-2026-82681 · Trilium+2 · Trilium+2

·

CVE-2026-53578

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Trilium versions prior to 0.104.0
Description The application fails to sanitize HTML for the mindMap note type during the Safe import process, which only applies sanitization to text notes. An attacker can provide a malicious import archive containing a mind map node with a dangerouslySetInnerHTML property. The Mind Elixir library assigns this property directly to a node's innerHTML, leading to the execution of arbitrary scripts when the victim opens the imported mind map. On the desktop client, because the Electron renderer runs with Node integration enabled, this cross-site scripting can escalate to full remote code execution on the host machine.
Recommendations Update to version 0.104.0.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53578
GHSA-RJ57-J38V-3577

Affected Products

Electron
Mind-Elixir
Trilium