Cross-Site Scripting Vulnerability in Trilium Note-Taking Application
CVE-2026-53579
9.3CRITICAL
What is CVE-2026-53579?
Trilium, an open-source hierarchical note-taking application, has a vulnerability where the 'Safe import' feature does not completely sanitize HTML content for book notes. This oversight allows an attacker to upload a specially crafted import archive containing malicious scripts. The affected content is executed in a user's environment when they open a note, leading to potential remote code execution. This issue compromises user safety as the Electron renderer on the desktop client runs with Node integration enabled, escalating the risk significantly. The vulnerability has been addressed in the latest version 0.104.0.
Affected Version(s)
Trilium < 0.104.0
