Executive brief
Trilium Notes, a self-hosted note-taking application, allows authenticated users to create "Web View" notes that embed external content. A flaw in the share renderer fails to properly escape user-supplied iframe URLs, permitting note authors to inject malicious JavaScript that executes when anyone—including administrators—views a shared note. An attacker can steal session cookies, read notes, execute scripts, or in some cases execute arbitrary code on the server.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw (CWE-79) in the share renderer's handling of the #webViewSrc label on Web View notes. The application sanitizes the label value to block dangerous URL schemes (e.g. javascript:) but does not HTML-escape the output before embedding it into an iframe src attribute in a server-rendered template. For relative URLs and non-HTTP schemes, the sanitizer returns the value unchanged; an attacker can break out of the src attribute by injecting a double quote and additional HTML attributes (e.g. onload handlers). The payload executes in the Trilium origin when any user opens the shared note link, giving the attacker the victim's session privileges. The fix, released in v0.105.0 (2026-08-19), properly HTML-escapes the sanitized URL before output.
Affected products
- Trilium Trilium Notes v0.104.1 and earlier
Timeline
- 2026-07-02: disclosed: Reported to maintainers via GitHub private security advisory
- 2026-08-19: patched: Fix released in v0.105.0; commits b139677e3 and cbae79bfa landed 2026-08-03
- 2026-09-13: advisory: Public advisory published by Voke Cyber
- 2026-09-14: other: CVE-2026-91021 published on NVD