CVE-2026-35593
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem. The uploadModifiedFileToAttachment function, which is called when a POST request is received to /api/attachments/{attachmentId}/upload-modified-file, replaces the content of the attachment with the content from another file (whose path is provided in filePath of Request body).
Leer descripción completaMostrar menos
After which the content of the attachment can be viewed at /api/attachments/{attachmentId}/download. This exposes sensitive system files such as SSH keys, credentials, configs, and OS files, potentially leading to remote code execution and compromise of co-hosted applications. This issue has been fixed in version 0.102.2.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.73%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-22, CWE-73
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-35593",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-35593",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-20T13:20:03.275700Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "TriliumNext",
"product": "Trilium",
"versions": [
{
"status": "affected",
"version": "< 0.102.2"
}
]
}
]
}
],
"published": "2026-05-20T00:16:37.433",
"references": [
{
"url": "https://github.com/TriliumNext/Trilium/releases/tag/v0.102.2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TriliumNext/Trilium/security/advisories/GHSA-hf4x-22rg-pjjp",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TriliumNext/Trilium/security/advisories/GHSA-hf4x-22rg-pjjp",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-22"
},
{
"lang": "en",
"value": "CWE-73"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem. The uploadModifiedFileToAttachment function, which is called when a POST request is received to /api/attachments/{attachmentId}/upload-modified-file, replaces the content of the attachment with the content from another file (whose path is provided in filePath of Request body). After which the content of the attachment can be viewed at /api/attachments/{attachmentId}/download. This exposes sensitive system files such as SSH keys, credentials, configs, and OS files, potentially leading to remote code execution and compromise of co-hosted applications. This issue has been fixed in version 0.102.2."
},
{
"lang": "es",
"value": "Trilium Notes es una aplicación de toma de notas jerárquica de código abierto y multiplataforma para construir grandes bases de conocimiento personales. Las versiones 0.102.1 y anteriores son vulnerables a la Inclusión Local de Ficheros, permitiendo a un atacante autenticado leer ficheros arbitrarios sensibles del sistema de ficheros del servidor. La función uploadModifiedFileToAttachment, que se llama cuando se recibe una solicitud POST en /api/attachments/{attachmentId}/upload-modified-file, reemplaza el contenido del adjunto con el contenido de otro fichero (cuya ruta se proporciona en filePath del cuerpo de la solicitud). Después de lo cual el contenido del adjunto puede verse en /api/attachments/{attachmentId}/download. Esto expone ficheros de sistema sensibles como claves SSH, credenciales, configuraciones y ficheros del sistema operativo, lo que podría conducir a la ejecución remota de código y al compromiso de aplicaciones co-alojadas. Este problema ha sido solucionado en la versión 0.102.2."
}
],
"lastModified": "2026-07-24T09:10:00.153",
"sourceIdentifier": "security-advisories@github.com"
}