Cross-Site Scripting Vulnerability in Trilium Note-Taking Application
CVE-2026-53579

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-53579?

Trilium, an open-source hierarchical note-taking application, has a vulnerability where the 'Safe import' feature does not completely sanitize HTML content for book notes. This oversight allows an attacker to upload a specially crafted import archive containing malicious scripts. The affected content is executed in a user's environment when they open a note, leading to potential remote code execution. This issue compromises user safety as the Electron renderer on the desktop client runs with Node integration enabled, escalating the risk significantly. The vulnerability has been addressed in the latest version 0.104.0.

Affected Version(s)

Trilium < 0.104.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.