Remote Code Execution Vulnerability in Trilium Note-Taking Application
CVE-2026-47727

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-47727?

Trilium, an open-source hierarchical note-taking application, contains a vulnerability allowing remote code execution due to the 'Safe import' filter failing to neutralize the shareTemplate relation. This issue occurs in versions before 0.104.0. Attackers can exploit this vulnerability by supplying an import archive that instantiates a server-side template, enabling unauthorized execution of JavaScript. When a victim subsequently publishes this note, the linked EJS code is processed on the server’s Node environment, granting the attacker full access to critical resources including the filesystem and network. This vulnerability emphasizes the importance of secure coding practices and was resolved in version 0.104.0.

Affected Version(s)

Trilium 0.104.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.