Trilium 是一款开源的分层笔记应用。在 0.104.0 版本之前,其“自动下载图片”功能会接受笔记中 标签里的 URL,并在没有任何路径校验的情况下读取所引用的本地文件,这使得任何经过身份验证的用户都可以读取 Trilium 进程有权限访问的任意文件。 当保存文本笔记时,Trilium 会扫描其中的 HTML,查找图片来源并下载所有外部资源。由于 HTML 清理器(sanitizer)将 方案(scheme)列为允许的方案,像 这样的源会直接传入文件系统读取操作,其内容随后被保存为笔记附件,用户即可获取该文件
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TriliumNext | Trilium | < 0.104.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53578 | 9.3 CRITICAL | Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml |
| CVE-2026-53579 | 9.3 CRITICAL | Trilium: Note Import to RCE via Book Note |
| CVE-2026-48996 | 9.3 CRITICAL | Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client |
| CVE-2026-47727 | 8.6 HIGH | Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass |
| CVE-2026-77438 | 7.5 HIGH | Trilium unauthenticated share-search discloses password-protected and hidden shared notes |
No comments yet