PT-2026-44939 · Unknown · Trilium Notes
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Trilium Notes versions prior to 0.102.2
Description
A malicious ZIP archive imported with safe import enabled can lead to remote code execution (RCE) and cross-site scripting (XSS). This is achieved through path traversal using the
#docName label. An attacker combines a payload note (type: code, mime: text/plain) containing raw HTML/JS with a trigger note (type: doc or type: launcher). The trigger note uses ../ path traversal in the #docName label to point to the payload note's API endpoint. Because the desktop client Electron renderer runs with nodeIntegration enabled, the RCE is triggered upon execution of the payload.Recommendations
Update to version 0.102.2.
Exploit
Fix
RCE
Path traversal
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trilium Notes