Security Flaw in Trilium Note-Taking Application by Trilium
CVE-2026-53580
What is CVE-2026-53580?
The Trilium note-taking application has a vulnerability in its default automatic image-download feature. In versions earlier than 0.104.0, the application fails to validate file paths when processing file:// URLs in img tags. This flaw allows authenticated users to access arbitrary local files by leveraging the application’s ability to read these files without proper controls. For instance, an attacker can use this weakness to retrieve sensitive files such as /etc/passwd or exploit the service by pointing to unbounded sources, potentially leading to server crashes due to uncontrolled memory allocation. With the feature enabled by default, it can be accessed via various interfaces like the web UI and ETAPI, highlighting the importance of prompting users to update to the fixed version, 0.104.0.
Affected Version(s)
Trilium < 0.104.0
