๐Ÿ” CVE Alert

CVE-2026-45733

HIGH 8.3

Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.

CWE CWE-79 CWE-83 CWE-693
Vendor triliumnext
Product trilium
Published Aug 18, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for triliumnext trilium

Be the first to know when new high vulnerabilities affecting triliumnext trilium are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

TriliumNext / Trilium
< 0.103.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/TriliumNext/Trilium/security/advisories/GHSA-h45q-4qc4-8hhg github.com: https://github.com/TriliumNext/Trilium/commit/c06939448bcc2879fc3c4d328ff7dc63ed6b5009 github.com: https://github.com/TriliumNext/Trilium/releases/tag/v0.103.0