CVE-2026-39309
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunAsNode fuse allows launching the app in a special Node.js mode using -e to execute arbitrary system commands with Trilium Notes's permissions and identity.
Leer descripción completaMostrar menos
An attacker can leverage this through a subprocess to request any sensitive permissions, such as access to hardware (camera, microphone) and TCC-protected files, causing the TCC system prompt to appear as if the request came from Trilium rather than the attacker's code, because macOS treats the subprocess as part of the parent application. Exploitation allows access to TCC-protected resources like the screen, camera, microphone, and folders such as ~/Documents and ~/Downloads, undermining macOS's security model and UI integrity through social engineering. This issue has been fixed in version 0.102.2.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-290, CWE-451
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-39309",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-39309",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-20T13:25:25.357157Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "TriliumNext",
"product": "Trilium",
"versions": [
{
"status": "affected",
"version": "< 0.102.2"
}
]
}
]
}
],
"published": "2026-05-20T00:16:37.613",
"references": [
{
"url": "https://github.com/TriliumNext/Trilium/releases/tag/v0.102.2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TriliumNext/Trilium/security/advisories/GHSA-66pm-8hvq-2wwx",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/TriliumNext/Trilium/security/advisories/GHSA-66pm-8hvq-2wwx",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-290"
},
{
"lang": "en",
"value": "CWE-451"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunAsNode fuse allows launching the app in a special Node.js mode using -e to execute arbitrary system commands with Trilium Notes's permissions and identity. An attacker can leverage this through a subprocess to request any sensitive permissions, such as access to hardware (camera, microphone) and TCC-protected files, causing the TCC system prompt to appear as if the request came from Trilium rather than the attacker's code, because macOS treats the subprocess as part of the parent application. Exploitation allows access to TCC-protected resources like the screen, camera, microphone, and folders such as ~/Documents and ~/Downloads, undermining macOS's security model and UI integrity through social engineering. This issue has been fixed in version 0.102.2."
},
{
"lang": "es",
"value": "Trilium Notes es una aplicación multiplataforma y jerárquica para tomar notas, enfocada en construir grandes bases de conocimiento personal. En las versiones 0.102.1 y anteriores, la configuración de Electron es vulnerable a un bypass de TCC a través de suplantación de avisos, permitiendo a atacantes locales activar avisos de permisos engañosos de macOS al ejecutar código malicioso bajo la identidad de la aplicación de confianza. La causa raíz es que el fusible RunAsNode permite iniciar la aplicación en un modo especial de Node.js usando -e para ejecutar comandos de sistema arbitrarios con los permisos e identidad de Trilium Notes. Un atacante puede aprovechar esto a través de un subproceso para solicitar cualquier permiso sensible, como acceso al hardware (cámara, micrófono) y archivos protegidos por TCC, haciendo que el aviso del sistema TCC aparezca como si la solicitud proviniera de Trilium en lugar del código del atacante, porque macOS trata el subproceso como parte de la aplicación principal. La explotación permite el acceso a recursos protegidos por TCC como la pantalla, cámara, micrófono y carpetas como ~/Documents y ~/Downloads, socavando el modelo de seguridad de macOS y la integridad de la interfaz de usuario a través de ingeniería social. Este problema ha sido solucionado en la versión 0.102.2."
}
],
"lastModified": "2026-07-24T09:10:00.153",
"sourceIdentifier": "security-advisories@github.com"
}