Cross-Site Scripting Vulnerability in Trilium Note-Taking Application
CVE-2026-48996
9.3CRITICAL
What is CVE-2026-48996?
In Trilium, an open-source hierarchical note-taking application, there is a significant vulnerability in versions up to 0.103.0 related to the 'Safe import' filter. This filter fails to sanitize note titles properly, allowing attackers to inject malicious scripts through the GeoMap note view. When a marker note with a crafted title is displayed, the script executes, taking advantage of the fact that the Electron renderer has Node integration enabled. This allows for escalation from cross-site scripting to full remote code execution on the user's system, making it crucial for users to upgrade to version 0.104.0 or later to mitigate this risk.
Affected Version(s)
Trilium < 0.104.0
