Stored Cross-Site Scripting in Trilium Notes by Open Note
CVE-2026-91021

Currently unrated

Key Information:

Vendor

Trilium

Vendor
CVE Published:
14 September 2026

What is CVE-2026-91021?

Trilium Notes, specifically versions up to v0.103.0, is susceptible to a stored cross-site scripting vulnerability in its share renderer for webView notes. The flaw stems from inadequate HTML escaping of user-controlled values in the #webViewSrc attribute, enabling attackers with note-authoring privileges to embed malicious JavaScript within shared notes. This injected code executes for any user who accesses the shared note, compromising user security across the platform, including for administrative accounts.

Affected Version(s)

Trillium Notes 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.