PT-2026-82682 · Trilium · Trilium
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Trilium versions prior to 0.104.0
Description
The Safe import filter fails to sanitize HTML for book note types, while only sanitizing text notes. This allows an attacker to provide a malicious import archive containing a payload that executes as a script. When a book note is displayed as a grid-view preview card, its content is injected into the page using the jQuery
html method. In the desktop client, the Electron renderer operates with Node integration enabled, allowing the injected JavaScript to escalate from cross-site scripting to remote code execution on the victim's machine.Recommendations
Update to version 0.104.0.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trilium