PT-2026-82682 · Trilium · Trilium

·

CVE-2026-53579

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Trilium versions prior to 0.104.0
Description The Safe import filter fails to sanitize HTML for book note types, while only sanitizing text notes. This allows an attacker to provide a malicious import archive containing a payload that executes as a script. When a book note is displayed as a grid-view preview card, its content is injected into the page using the jQuery html method. In the desktop client, the Electron renderer operates with Node integration enabled, allowing the injected JavaScript to escalate from cross-site scripting to remote code execution on the victim's machine.
Recommendations Update to version 0.104.0.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53579
GHSA-H7W4-CJFG-CVJ8

Affected Products

Trilium