← Späť na vyhľadávanie CVE

CVE-2026-47727

Trilium

Popis

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on -Safe import- filter fails to neutralize the shareTemplate relation because that relation is not marked as dangerous, allowing an attacker-supplied import archive to plant a server-side template that leads to remote code execution. The relation is omitted from the built-in list of dangerous attributes, so unlike other code-loading relations it is not disabled on import, and when the victim later publishes the imported note the public share renderer feeds the linked EJS code note-s raw bytes into ejs.render, which compiles them in the server-s Node process. An unauthenticated request to the shared note then executes the attacker-s JavaScript with full access to require, process, the filesystem, and the network. This issue is fixed in version 0.104.0.

CVSS 8.6EPSS 0.434%Riziko 0.89
Zobraziť zdroj
Zverejnené
2026-08-27 20:17:44
Dotknuté verzie
<0.104.0
Typ
Webová aplikácia
Posledná úprava
2026-08-27 20:17:44
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X