Junglewise Threat Intelligence

CVE-2026-53578: Trilium mindMap note import remote code execution

CVE-2026-53578 · Severity: info · CVSS 9.3 · Published 2026-08-27

Technologies: TriliumNext Trilium. Vendors: TriliumNext.

Executive brief

Trilium is an open-source hierarchical note-taking application that allows users to import notes from archive files. The application's "Safe import" filter, which is enabled by default, sanitizes HTML in text notes but fails to sanitize mindMap notes, allowing attackers to embed arbitrary HTML and JavaScript in imported malicious note archives. On the desktop client, the injected JavaScript runs with Node.js integration enabled, escalating to full remote code execution on the victim's machine.

Technical details

The vulnerability is a stored cross-site scripting (XSS) to remote code execution chain caused by incomplete HTML sanitization in the Safe import filter. The mindMap note type is excluded from sanitization logic, and its JSON content is parsed directly and passed to the Mind Elixir library via the init() function without validation. The Mind Elixir library exposes a dangerouslySetInnerHTML property that assigns user-controlled content directly to a DOM node's innerHTML. The Electron desktop client has nodeIntegration enabled in the renderer process, allowing injected JavaScript to call child_process.exec() and execute arbitrary commands. An attacker can craft a malicious note archive containing a mindMap note with a dangerouslySetInnerHTML payload that executes system commands when the victim imports and opens the note. The vulnerability is fixed in version 0.104.0.

Affected products

  • TriliumNext Trilium up to and including 0.103.0

Timeline

  • 2026-08-20: disclosed
  • 2026-06-01: patched: Fix committed to repository; version 0.104.0 released

References

Related threats