Exposed Search Functionality in Trilium Note-Taking Application
CVE-2026-77438
7.5HIGH
What is CVE-2026-77438?
The Trilium Note-Taking Application has a vulnerability that compromises the security of protected notes. In versions up to and including 0.103.0, the public share-search endpoint fails to properly enforce access controls for individual notes. As a result, an unauthorized user can access titles, tree paths, and contents of notes that should be secured. The endpoint only checks the authorization of the ancestor note and does not verify if each specific note requires additional authentication. This allows attackers to perform full-text searches across protected notes and retrieve sensitive information without permission. The issue is resolved in version 0.104.0.
Affected Version(s)
Trilium < 0.104.0
