PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39311 TriliumNext CVE debrief

CVE-2026-39311 affects Trilium Notes versions 0.102.1 and earlier. The supplied sources describe a critical attack chain where an attacker can abuse an unsanitized SVG attachment, run script in the application origin because Content Security Policy is disabled, read a CSRF token from the page, and then call the backend script execution API to execute arbitrary Node.js code on the server. The issue is fixed in version 0.102.2. NVD currently lists the vulnerability as CVSS 3.1 6.8 Medium, with network attack vector but requiring user interaction and elevated privileges in the scoring model.

Vendor
TriliumNext
Product
Trilium
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-23
Advisory published
2026-05-20
Advisory updated
2026-07-23

Who should care

Administrators and operators of Trilium Notes instances, especially any deployment that lets users open or share SVG attachments, should treat this as urgent. Security teams should also care if the application is exposed to non-trusted users or used to store shared content.

Technical summary

According to the supplied description, Trilium serves SVG attachments as image/svg+xml without sanitization and has CSP disabled. A malicious SVG can therefore execute in the browser under the application origin. From that origin, the attacker can fetch the page, extract the csrfToken from the document body, and submit a signed request to /api/script/exec. Because that API can execute Node.js code on the server, the result is server compromise when a user views the malicious SVG.

Defensive priority

High

Recommended defensive actions

  • Upgrade Trilium Notes to version 0.102.2 or later.
  • Review whether SVG attachments are accepted, shared, or rendered in your deployment and restrict them where possible.
  • Confirm that access to the application is limited to trusted users until patching is complete.
  • Audit any exposure of the /api/script/exec endpoint and restrict it to the minimum necessary use.
  • Check logs and server state for suspicious SVG attachment access or unexpected script execution activity.

Evidence notes

This debrief is based only on the supplied CVE record, NVD metadata, and the referenced GitHub release/advisory links. The corpus explicitly states the affected versions, the unsanitized SVG plus disabled CSP attack path, the CSRF token extraction step, the /api/script/exec endpoint abuse, and the fix in 0.102.2. NVD metadata also supplies the CVSS vector and weakness classifications (CWE-79 and CWE-94).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39311 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39311

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39311 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39311

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.