PT-2026-82734 · Trilium · Trilium
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trilium versions prior to 0.104.0
Description
The public share-search endpoint does not enforce
shareCredentials and shareHiddenFromTree controls. The endpoint authorizes only the ancestor note provided in the request and performs a full-text search across the published subtree, returning the title, share identifier, and hierarchical path of matching notes without verifying if the individual note requires a password or is hidden. An unauthenticated visitor can use this endpoint as a boolean oracle—a system that provides a yes/no answer to a query—to confirm arbitrary substrings and recover the full content of protected shared notes.Recommendations
Update to version 0.104.0.
Exploit
Fix
Information Disclosure
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trilium