PT-2026-82681 · Trilium+2 · Trilium+2
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Trilium versions prior to 0.104.0
Description
The application fails to sanitize HTML for the mindMap note type during the Safe import process, which only applies sanitization to text notes. An attacker can provide a malicious import archive containing a mind map node with a
dangerouslySetInnerHTML property. The Mind Elixir library assigns this property directly to a node's innerHTML, leading to the execution of arbitrary scripts when the victim opens the imported mind map. On the desktop client, because the Electron renderer runs with Node integration enabled, this cross-site scripting can escalate to full remote code execution on the host machine.Recommendations
Update to version 0.104.0.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Electron
Mind-Elixir
Trilium