Trilium 是一款开源的层级式笔记应用。在截至 0.103.0 的版本中,默认启用的“安全导入”过滤器仅对文本类笔记进行 HTML 净化,而排除了思维导图(mindMap)笔记类型——其 JSON 内容在未经验证的情况下直接存储。这导致攻击者提供的导入压缩包可以嵌入负载(payload),使其以任意 HTML 的形式渲染。思维导图节点可以携带一个 属性,Mind Elixir 库会将该属性直接赋值给节点的 ,因此恶意笔记在通过“安全导入”后,一旦受害者打开导入的思维导图,其中的脚本就会立即执行。在桌面客户端中,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TriliumNext | Trilium | < 0.104.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53579 | 9.3 CRITICAL | Trilium: Note Import to RCE via Book Note |
| CVE-2026-48996 | 9.3 CRITICAL | Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client |
| CVE-2026-47727 | 8.6 HIGH | Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass |
| CVE-2026-53580 | 8.1 HIGH | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image- |
| CVE-2026-77438 | 7.5 HIGH | Trilium unauthenticated share-search discloses password-protected and hidden shared notes |
No comments yet