« Volver al listado

CVE-2026-39309

Estado: AplazadaMedia (5.5)—

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunAsNode fuse allows launching the app in a special Node.js mode using -e to execute arbitrary system commands with Trilium Notes's permissions and identity.

Leer descripción completaMostrar menos

An attacker can leverage this through a subprocess to request any sensitive permissions, such as access to hardware (camera, microphone) and TCC-protected files, causing the TCC system prompt to appear as if the request came from Trilium rather than the attacker's code, because macOS treats the subprocess as part of the parent application. Exploitation allows access to TCC-protected resources like the screen, camera, microphone, and folders such as ~/Documents and ~/Downloads, undermining macOS's security model and UI integrity through social engineering. This issue has been fixed in version 0.102.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-39309",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-39309",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-20T13:25:25.357157Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "TriliumNext",
          "product": "Trilium",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.102.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-20T00:16:37.613",
  "references": [
    {
      "url": "https://github.com/TriliumNext/Trilium/releases/tag/v0.102.2",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/TriliumNext/Trilium/security/advisories/GHSA-66pm-8hvq-2wwx",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/TriliumNext/Trilium/security/advisories/GHSA-66pm-8hvq-2wwx",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        },
        {
          "lang": "en",
          "value": "CWE-451"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunAsNode fuse allows launching the app in a special Node.js mode using -e to execute arbitrary system commands with Trilium Notes's permissions and identity. An attacker can leverage this through a subprocess to request any sensitive permissions, such as access to hardware (camera, microphone) and TCC-protected files, causing the TCC system prompt to appear as if the request came from Trilium rather than the attacker's code, because macOS treats the subprocess as part of the parent application. Exploitation allows access to TCC-protected resources like the screen, camera, microphone, and folders such as ~/Documents and ~/Downloads, undermining macOS's security model and UI integrity through social engineering. This issue has been fixed in version 0.102.2."
    },
    {
      "lang": "es",
      "value": "Trilium Notes es una aplicación multiplataforma y jerárquica para tomar notas, enfocada en construir grandes bases de conocimiento personal. En las versiones 0.102.1 y anteriores, la configuración de Electron es vulnerable a un bypass de TCC a través de suplantación de avisos, permitiendo a atacantes locales activar avisos de permisos engañosos de macOS al ejecutar código malicioso bajo la identidad de la aplicación de confianza. La causa raíz es que el fusible RunAsNode permite iniciar la aplicación en un modo especial de Node.js usando -e para ejecutar comandos de sistema arbitrarios con los permisos e identidad de Trilium Notes. Un atacante puede aprovechar esto a través de un subproceso para solicitar cualquier permiso sensible, como acceso al hardware (cámara, micrófono) y archivos protegidos por TCC, haciendo que el aviso del sistema TCC aparezca como si la solicitud proviniera de Trilium en lugar del código del atacante, porque macOS trata el subproceso como parte de la aplicación principal. La explotación permite el acceso a recursos protegidos por TCC como la pantalla, cámara, micrófono y carpetas como ~/Documents y ~/Downloads, socavando el modelo de seguridad de macOS y la integridad de la interfaz de usuario a través de ingeniería social. Este problema ha sido solucionado en la versión 0.102.2."
    }
  ],
  "lastModified": "2026-07-24T09:10:00.153",
  "sourceIdentifier": "security-advisories@github.com"
}