Junglewise Threat Intelligence

CVE-2026-45668: Trilium Notes RCE via path traversal in ZIP import

CVE-2026-45668 · Severity: info · CVSS 9.3 · Published 2026-05-29

Vendors: TriliumNext.

Executive brief

Trilium Notes is a hierarchical note-taking application used to build personal knowledge bases. A security vulnerability allows an attacker to execute malicious code on a user's computer if the user imports a specially crafted ZIP archive, even if 'Safe Import' mode is enabled. This could lead to a full system compromise, allowing an attacker to steal data, install malware, or disrupt operations.

Technical details

Trilium Notes prior to version 0.102.2 is vulnerable to Remote Code Execution (RCE) triggered by a malicious ZIP archive import. The vulnerability stems from a path traversal flaw in the '#docName' label handling within the Doc renderer component. An attacker can craft a ZIP file containing a payload note (type: code, mime: text/plain) and a trigger note (type: doc or launcher) that uses a '../' sequence in its #docName attribute to point to the payload's API endpoint. Because 'Safe Import' does not sanitize text/plain notes or the docName label, the payload is stored and then executed via XSS when the trigger note is rendered. Since the Electron desktop client runs with 'nodeIntegration' enabled, the XSS leads directly to RCE. The issue is fixed in version 0.102.2.

Affected products

  • TriliumNext Trilium Notes < 0.102.2

Timeline

  • 2026-05-11: advisory: GitHub advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References