Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77438— Trilium unauthenticated share-search discloses password-protected and hidden shared notes

Quick assessment

Affected
TriliumNext Trilium
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Trilium 是一款开源的层级化笔记应用程序。在包括 0.103.0 及更早的版本中,公开分享搜索端点未强制执行每个笔记的 和 控制,使得未认证的访问者能够读取受保护的共享笔记的标题、树路径和内容。该端点仅对请求中提供的祖先笔记进行授权,随后在整个已发布的子树上执行全文搜索,并返回每个匹配笔记的标题、共享标识符和层级路径,而不会重新检查该笔记是否要求共享密码或是否从导航树中隐藏。由于搜索会匹配笔记内容,攻击者可以枚举受保护的笔记,并将该端点用作布尔神谕(boolean oracle),从而确认任意子串的存在,进而

CVSS 7.5 · High EPSS 0.24% · P15

Affected Version Matrix 1

VendorProduct Version RangeStatus
TriliumNext Trilium < 0.104.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77438

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Trilium unauthenticated share-search discloses password-protected and hidden shared notes
Source: CVE Program / CVE List V5
Vulnerability Description
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and then runs a full-text search across the entire published subtree, returning each matching note's title, share identifier, and hierarchical path without re-checking whether that individual note requires a share password or is hidden from the navigation tree. Because the search matches note content, an attacker can enumerate protected notes and use the endpoint as a boolean oracle that confirms arbitrary substrings, recovering the full contents of notes that should be gated behind a password. This issue is fixed in version 0.104.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TriliumNext Trilium < 0.104.0 -

II. Public POCs for CVE-2026-77438

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77438

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77438 (1)

Vendor Advisories for CVE-2026-77438 (1)

Same Patch Batch · TriliumNext · 2026-08-27 · 6 CVEs total

CVE-2026-53578 9.3 CRITICAL Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml
CVE-2026-53579 9.3 CRITICAL Trilium: Note Import to RCE via Book Note
CVE-2026-48996 9.3 CRITICAL Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client
CVE-2026-47727 8.6 HIGH Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass
CVE-2026-53580 8.1 HIGH Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-

IV. Related Vulnerabilities

V. Comments for CVE-2026-77438

No comments yet


Leave a comment