Remote Code Execution Vulnerability in Trilium Note-Taking Application
CVE-2026-47727
8.6HIGH
What is CVE-2026-47727?
Trilium, an open-source hierarchical note-taking application, contains a vulnerability allowing remote code execution due to the 'Safe import' filter failing to neutralize the shareTemplate relation. This issue occurs in versions before 0.104.0. Attackers can exploit this vulnerability by supplying an import archive that instantiates a server-side template, enabling unauthorized execution of JavaScript. When a victim subsequently publishes this note, the linked EJS code is processed on the server’s Node environment, granting the attacker full access to critical resources including the filesystem and network. This vulnerability emphasizes the importance of secure coding practices and was resolved in version 0.104.0.
Affected Version(s)
Trilium 0.104.0
