Executive brief
Trilium Notes, a personal knowledge base and note-taking application, contains a security flaw that allows authorized users to access sensitive files on the host server. By exploiting this vulnerability, an attacker with high-level privileges could read system configuration files, SSH keys, or credentials. This could lead to a complete compromise of the server, including other applications hosted on the same machine.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the `uploadModifiedFileToAttachment` and `uploadModifiedFileToNote` functions of Trilium Notes. These functions, triggered via POST requests to `/api/attachments/{attachmentId}/upload-modified-file` and similar note endpoints, accept a `filePath` parameter in the request body without proper validation or sanitization. An authenticated attacker with high privileges can provide an absolute path (e.g., `/etc/passwd`) to overwrite an attachment's content with the contents of a system file. The stolen data can then be retrieved via the `/api/attachments/{attachmentId}/download` endpoint. This issue is fixed in version 0.102.2 by implementing stricter input validation.
Affected products
- TriliumNext Trilium Notes <= 0.102.1
Timeline
- 2026-04-05: patched: Version 0.102.2 released with security fixes.
- 2026-05-11: advisory: GitHub Security Advisory GHSA-hf4x-22rg-pjjp published.
- 2026-05-20: disclosed: CVE-2026-35593 published to NVD.