Security Flaw in Trilium Note-Taking Application by Trilium
CVE-2026-53580

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-53580?

The Trilium note-taking application has a vulnerability in its default automatic image-download feature. In versions earlier than 0.104.0, the application fails to validate file paths when processing file:// URLs in img tags. This flaw allows authenticated users to access arbitrary local files by leveraging the application’s ability to read these files without proper controls. For instance, an attacker can use this weakness to retrieve sensitive files such as /etc/passwd or exploit the service by pointing to unbounded sources, potentially leading to server crashes due to uncontrolled memory allocation. With the feature enabled by default, it can be accessed via various interfaces like the web UI and ETAPI, highlighting the importance of prompting users to update to the fixed version, 0.104.0.

Affected Version(s)

Trilium < 0.104.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.