Cross-Site Scripting Vulnerability in Trilium Note-Taking Application
CVE-2026-48996

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-48996?

In Trilium, an open-source hierarchical note-taking application, there is a significant vulnerability in versions up to 0.103.0 related to the 'Safe import' filter. This filter fails to sanitize note titles properly, allowing attackers to inject malicious scripts through the GeoMap note view. When a marker note with a crafted title is displayed, the script executes, taking advantage of the fact that the Electron renderer has Node integration enabled. This allows for escalation from cross-site scripting to full remote code execution on the user's system, making it crucial for users to upgrade to version 0.104.0 or later to mitigate this risk.

Affected Version(s)

Trilium < 0.104.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.