PT-2026-82683 · Trilium · Trilium
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Trilium versions prior to 0.104.0
Description
The automatic image-download feature fails to validate paths when processing
file:// URLs within img tags of a note. This allows an authenticated user to disclose arbitrary files readable by the process by saving a text note with a source like file:///etc/passwd, which the system then stores as a note attachment. Additionally, targeting an unbounded source such as /dev/zero can lead to uncontrolled memory allocation, resulting in a server process crash. This functionality is enabled by default and accessible via the web UI, the ETAPI, the web clipper, and note imports, requiring an authenticated session or an ETAPI token.Recommendations
Update to version 0.104.0.
Exploit
Fix
Resource Exhaustion
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trilium