Trilium 是一款开源的层级化笔记应用程序。在包括 0.103.0 及更早的版本中,公开分享搜索端点未强制执行每个笔记的 和 控制,使得未认证的访问者能够读取受保护的共享笔记的标题、树路径和内容。该端点仅对请求中提供的祖先笔记进行授权,随后在整个已发布的子树上执行全文搜索,并返回每个匹配笔记的标题、共享标识符和层级路径,而不会重新检查该笔记是否要求共享密码或是否从导航树中隐藏。由于搜索会匹配笔记内容,攻击者可以枚举受保护的笔记,并将该端点用作布尔神谕(boolean oracle),从而确认任意子串的存在,进而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TriliumNext | Trilium | < 0.104.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TriliumNext | Trilium | < 0.104.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53578 | 9.3 CRITICAL | Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml |
| CVE-2026-53579 | 9.3 CRITICAL | Trilium: Note Import to RCE via Book Note |
| CVE-2026-48996 | 9.3 CRITICAL | Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client |
| CVE-2026-47727 | 8.6 HIGH | Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass |
| CVE-2026-53580 | 8.1 HIGH | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image- |
No comments yet