These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-77438 is a vulnerability in Trilium, an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce per-note shareCredentials and shareHiddenFromTree controls. This allows an unauthenticated visitor to read titles, tree paths, and content of protected shared notes. The issue is fixed in version 0.104.0.
CVE-2026-53580 is a high-severity vulnerability in Trilium, an open-source hierarchical note-taking application. The vulnerability allows an authenticated user to disclose arbitrary files readable by the Trilium process by exploiting the automatic image-download feature. This feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation. The issue is fixed i [truncated]
A critical vulnerability exists in Trilium, an open-source hierarchical note-taking application, versions up to and including 0.103.0. The application's 'Safe import' filter does not sanitize HTML for book notes, allowing an attacker to embed a malicious payload that executes as script when a victim opens the containing note. This issue is fixed in version 0.104.0.
CVE-2026-53578 is a critical vulnerability in Trilium, an open-source hierarchical note-taking application. The 'Safe import' feature does not properly sanitize HTML in mindMap notes, allowing an attacker to embed a payload that executes as arbitrary HTML. When the victim opens the imported mind map using the desktop client with Node integration enabled, the injected JavaScript escalates to full remote co [truncated]
A critical vulnerability exists in Trilium, an open-source hierarchical note-taking application, versions up to and including 0.103.0. The application's 'Safe import' filter does not sanitize note titles properly, and the GeoMap note view renders marker note titles as raw HTML, allowing attackers to inject scripts via specially crafted import archives. When opened in the GeoMap, these scripts execute, lea [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:44.780Z and has not been modified since then. The NVD entry is currently 8.6 HIGH. This vulnerability affects Trilium's hierarchical note-taking application, specifically versions prior to 0.104.0, due to the default-on 'Safe import' filter failing to neutralize the shareTemplate relation. [truncated]
CVE-2026-45733 is a high-severity vulnerability in Trilium Notes, a cross-platform note-taking application. The vulnerability allows a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J, enabling an attacker to run operating-system commands as the victim. This issue is fixed in version 0.103.0. Defenders should assess exposure and prioritize patching to prevent exploitati [truncated]
CVE-2026-39311 affects Trilium Notes versions 0.102.1 and earlier. The supplied sources describe a critical attack chain where an attacker can abuse an unsanitized SVG attachment, run script in the application origin because Content Security Policy is disabled, read a CSRF token from the page, and then call the backend script execution API to execute arbitrary Node.js code on the server. The issue is fixe [truncated]
CVE-2026-39310 is a high-severity authentication-bypass issue in Trilium Notes Desktop versions 0.102.1 and earlier. In an Electron environment, Trilium disables authentication middleware for the Clipper API, which can leave endpoints such as /api/clipper/notes reachable without a password, API token, or CSRF protection. The supplied advisory indicates that an attacker on the same network can discover exp [truncated]
CVE-2026-39309 affects Trilium Notes versions 0.102.1 and earlier. According to the supplied NVD record and GitHub references, the issue is a macOS TCC bypass through prompt spoofing in the Electron configuration: a local attacker can abuse the app’s RunAsNode fuse to launch a Node.js subprocess and trigger misleading permission prompts that appear to come from Trilium Notes. The result is a UI and trust [truncated]
CVE-2026-35593 is an authenticated local file inclusion issue in Trilium Notes 0.102.1 and earlier. The vulnerable attachment upload path can be pointed at another file on the server, causing the attachment content to be replaced with the contents of that file and later retrieved through the attachment download endpoint. Per the advisory and NVD record, this can expose sensitive local files such as SSH ke [truncated]