Impact
Trilium Notes introduced a stored cross‑site scripting flaw in the share renderer for webView notes. The vulnerability arises from inadequate HTML escaping of the user‑controlled #webViewSrc parameter, allowing a note author to inject malicious JavaScript. When any user—including administrators—opens the compromised note, the injected code runs in the context of the victim’s browser, potentially leading to data theft, credential compromise, or the execution of arbitrary client‑side instructions.
Affected Systems
Trilium Notes versions 0.103.0 and earlier are affected. The flaw affects any installation that utilizes the share renderer to publish notes via webView, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and there is no EPSS score available. The flaw is not listed in the CISA KEV catalog. Attackers need only note‑authoring privileges to embed the payload, and the exploitation occurs when a target user opens the shared note. The path is internal to the application, requiring no external network interaction beyond the share action.
OpenCVE Enrichment