CVE-2026-45668: Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type: launcher) with a #docName label that uses ../ path traversal to point at the payload note's API endpoint. The desktop client Electron renderer runs with nodeIntegration enabled, so an RCE is triggered once the payload is executed. This vulnerability is fixed in 0.102.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trilium Notesto a version that resolves this vulnerability.Fixed in 0.102.2 - Compensating control
If you cannot upgrade to 0.102.2 immediately, disable Safe Import (Safe Import enabled is required for the described #docName path traversal + XSS chain).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45668?
CVE-2026-45668 has a critical severity rating of 9.3.
What type of vulnerability is CVE-2026-45668?
CVE-2026-45668 is classified as a Path Traversal and XSS vulnerability.
How do I fix CVE-2026-45668?
To fix CVE-2026-45668, update to Trilium Notes version 0.102.2 or later.
What impact does CVE-2026-45668 have?
CVE-2026-45668 can lead to remote code execution through a malicious ZIP archive.
Is CVE-2026-45668 present in earlier versions of Trilium Notes?
Yes, CVE-2026-45668 exists in all versions of Trilium Notes prior to 0.102.2.