CVE-2026-53578: Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml

Published Aug 27, 2026
·
Updated

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed a payload that renders as arbitrary HTML. A mind map node can carry a dangerouslySetInnerHTML property that the Mind Elixir library assigns directly to a node's innerHTML, so a malicious note survives Safe import and executes script as soon as the victim opens the imported mind map. On the desktop client the Electron renderer runs with Node integration enabled, so the injected JavaScript escalates from cross-site scripting to full remote code execution on the victim's machine. This issue is fixed in version 0.104.0.

Affected Software

1 affected component
Trilium Trilium<=0.103.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 0.104.0

Event History

Aug 27, 2026
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to remote code execution?

Users of the Trilium desktop client who import a malicious archive and then open its included mind map are exposed. The Electron renderer has Node integration enabled, allowing injected JavaScript to execute code on the victim's machine.

2

Does enabling Safe import prevent exploitation?

No. Safe import is enabled by default, but it sanitizes HTML only for text notes and does not sanitize mindMap note content.

3

What attacker interaction is required?

An attacker must provide a crafted import archive. The victim must import it and open the malicious mind map for the payload to execute.

4

What should be done if patching cannot happen immediately?

Do not import archives from untrusted sources, and avoid opening mind maps from previously imported untrusted archives. The issue is fixed in version 0.104.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203