Trilium 是一款开源的层级化笔记应用。在 0.104.0 版本之前,默认启用的“安全导入”过滤器未能中和 关系,因为该关系未被标记为危险属性,导致攻击者提供的导入归档文件可以植入一个服务器端模板,从而引发远程代码执行。由于该关系未列入内置的危险属性列表,因此与其他代码加载关系不同,它在导入时未被禁用。当受害者随后发布该导入的笔记时,公共分享渲染器会将所链接的 EJS 代码笔记的原始字节传递给 ,进而在服务器的 Node 进程中编译执行。此时,对共享笔记发起的一个未经身份验证的请求即可执行攻击者的 JavaSc
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TriliumNext | Trilium | 0.104.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53578 | 9.3 CRITICAL | Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml |
| CVE-2026-53579 | 9.3 CRITICAL | Trilium: Note Import to RCE via Book Note |
| CVE-2026-48996 | 9.3 CRITICAL | Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client |
| CVE-2026-53580 | 8.1 HIGH | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image- |
| CVE-2026-77438 | 7.5 HIGH | Trilium unauthenticated share-search discloses password-protected and hidden shared notes |
No comments yet