Executive brief
Trilium is an open-source note-taking application that allows users to share note hierarchies publicly on the web. An attacker can bypass password-protection and visibility controls by exploiting a flaw in the public search endpoint, reading the titles, tree paths, and full content of notes that should be gated behind credentials or hidden from the navigation tree. This allows sensitive shared notes to be discovered and their content recovered without knowing the intended password.
Technical details
The vulnerability is a broken access control (CWE-863) in the GET /share/api/notes search endpoint. The endpoint authorizes only the ancestor note supplied in the request, then performs a full-text search (including note content) across the entire published subtree without re-checking per-note shareCredentials or shareHiddenFromTree protections. An unauthenticated attacker can enumerate protected notes by their titles and paths, and use the endpoint as a boolean oracle to confirm arbitrary substrings of note content, recovering full contents of password-protected notes. The direct content routes enforce these controls via checkNoteAccess(), but the search endpoint bypasses this check. The vulnerability is fixed in version 0.104.0 by applying the same per-note authorization checks to search results.
Affected products
- TriliumNext Trilium up to and including 0.103.0
Timeline
- 2026-08-27: disclosed: Published in NVD
- 2026-07-13: patched: Fix committed to main branch; version 0.104.0 released