PT-2026-44939 · Unknown · Trilium Notes

·

CVE-2026-45668

·

Published

2026-05-29

·

Updated

2026-07-22

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Trilium Notes versions prior to 0.102.2
Description A malicious ZIP archive imported with safe import enabled can lead to remote code execution (RCE) and cross-site scripting (XSS). This is achieved through path traversal using the #docName label. An attacker combines a payload note (type: code, mime: text/plain) containing raw HTML/JS with a trigger note (type: doc or type: launcher). The trigger note uses ../ path traversal in the #docName label to point to the payload note's API endpoint. Because the desktop client Electron renderer runs with nodeIntegration enabled, the RCE is triggered upon execution of the payload.
Recommendations Update to version 0.102.2.

Exploit

Fix

RCE

Path traversal

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45668
GHSA-9JJC-CCCQ-F6RH

Affected Products

Trilium Notes