Stored Cross-Site Scripting in Trilium Notes by Open Note
CVE-2026-91021
Currently unrated
What is CVE-2026-91021?
Trilium Notes, specifically versions up to v0.103.0, is susceptible to a stored cross-site scripting vulnerability in its share renderer for webView notes. The flaw stems from inadequate HTML escaping of user-controlled values in the #webViewSrc attribute, enabling attackers with note-authoring privileges to embed malicious JavaScript within shared notes. This injected code executes for any user who accesses the shared note, compromising user security across the platform, including for administrative accounts.
Affected Version(s)
Trillium Notes 0
