Executive brief
Trilium is an open-source note-taking application that allows users to import note archives and publish notes for sharing. A flaw in the default-enabled "Safe import" filter allows attackers to bypass code-execution safeguards by importing a malicious archive. When a victim publishes an imported note via the share feature, the attacker's JavaScript executes on the server with full system access, enabling complete system compromise.
Technical details
The vulnerability is a server-side template injection (SSTI) in EJS templating caused by incomplete hardening of dangerous attributes. The shareTemplate relation was not marked isDangerous in BUILTIN_ATTRIBUTES, so the default-on "Safe import" filter failed to neutralize it during import by prefixing disabled:. An attacker can craft a ZIP archive containing a note with a shareTemplate relation pointing to an EJS code note filled with arbitrary JavaScript. When the victim publishes the imported note via the /share/ endpoint, the public-share renderer invokes ejs.render() on the attacker-supplied template without sandboxing, executing code with full access to require, process, filesystem, and network. No authentication is required for the RCE trigger (unauthenticated GET /share/). The fix in version 0.104.0 adds isDangerous: true to the shareTemplate relation definition.
Affected products
- Trilium Trilium <0.104.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Version 0.104.0 released