CVE-2025-68621: Trilium Notes has a Timing Attack Vulnerability in /api/login/sync
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes byte-by-byte through statistical timing analysis. This enables complete authentication bypass without password knowledge, granting full read/write access to victim's knowledge base. This vulnerability is fixed in 0.101.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68621?
CVE-2025-68621 is classified as a critical vulnerability due to its potential for timing attacks in the authentication process.
How do I fix CVE-2025-68621?
To remediate CVE-2025-68621, upgrade Trilium Notes to version 0.101.0 or later.
What component is affected by CVE-2025-68621?
CVE-2025-68621 affects the /api/login/sync endpoint in Trilium Notes.
What can happen if CVE-2025-68621 is exploited?
If exploited, CVE-2025-68621 could allow attackers to determine valid authentication tokens through timing attacks.
Is CVE-2025-68621 present in all versions of Trilium Notes?
CVE-2025-68621 is present in all versions of Trilium Notes prior to 0.101.0.