PT-2026-82683 · Trilium · Trilium

·

CVE-2026-53580

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Trilium versions prior to 0.104.0
Description The automatic image-download feature fails to validate paths when processing file:// URLs within img tags of a note. This allows an authenticated user to disclose arbitrary files readable by the process by saving a text note with a source like file:///etc/passwd, which the system then stores as a note attachment. Additionally, targeting an unbounded source such as /dev/zero can lead to uncontrolled memory allocation, resulting in a server process crash. This functionality is enabled by default and accessible via the web UI, the ETAPI, the web clipper, and note imports, requiring an authenticated session or an ETAPI token.
Recommendations Update to version 0.104.0.

Exploit

Fix

Resource Exhaustion

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53580
GHSA-3GXR-J6G6-Q75C

Affected Products

Trilium