Executive brief
TidGi Desktop, a personal knowledge management application, is vulnerable to a critical security flaw that allows an attacker to execute arbitrary commands on a user's computer. This occurs when a user imports a specially crafted TiddlyWiki repository from a malicious source or Git URL. Successful exploitation could lead to complete system takeover, data theft, or the installation of malware.
Technical details
TidGi Desktop through 0.13.0 contains a remote code execution vulnerability triggered during the wiki import and boot process. The application automatically loads all '.tid' files from the 'tiddlers/' directory into the wiki store. TiddlyWiki's core boot logic then identifies any tiddler with a 'module-type' field set to 'startup' and 'type' set to 'application/javascript', registering and executing its content as a Node.js module. Because these modules execute with full access to Node.js built-ins like 'child_process', an attacker can achieve arbitrary command execution by providing a malicious repository. No patches are currently available; users should avoid importing untrusted repositories.
Affected products
- Lin Onetwo (tiddly-gittly) TidGi Desktop <= 0.13.0
Timeline
- 2026-06-04: disclosed: Initial disclosure on GitHub Advisory Database
- 2026-07-14: advisory: Advisory updated