Arbitrary HTML Injection Vulnerability in Trilium Note-Taking Application
CVE-2026-53578
9.3CRITICAL
What is CVE-2026-53578?
The Trilium note-taking application has a flaw in its default 'Safe import' filter that fails to sanitize JSON content for mindMap note types. Attackers can exploit this vulnerability to embed malicious payloads within imported mind map nodes. When a victim opens an imported mind map, the payload executes as arbitrary HTML through the dangerouslySetInnerHTML property, leading to potential full remote code execution. This issue was addressed in version 0.104.0, emphasizing the importance of updating to secure versions to protect against such attacks.
Affected Version(s)
Trilium < 0.104.0
