CVE-2026-91021: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Trilium Trillium Notes
Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators.
AI Analysis
Technical Summary
CVE-2026-91021 is a stored cross-site scripting vulnerability in Trilium Notes (up to version 0.103.0) caused by improper neutralization of input during web page generation. Specifically, the share renderer for webView notes fails to properly escape user-controlled #webViewSrc values, enabling injection of arbitrary JavaScript code. An attacker with note-authoring privileges can exploit this to execute scripts in the context of other users viewing the shared note.
Potential Impact
An attacker with note-authoring privileges can inject malicious JavaScript that executes in the browsers of users who open the shared note, including administrators. This can lead to unauthorized actions performed on behalf of the victim, theft of sensitive information, or further compromise of user accounts. The vulnerability affects the confidentiality and integrity of user data within the application.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Users should exercise caution when sharing notes and restrict note-authoring privileges to trusted users only. Monitor the vendor's advisory channels for updates and apply any forthcoming patches promptly. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-91021: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Trilium Trillium Notes
Description
Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators.
CVSS v3.1
Score 5.4medium
Affected software
Trilium
Trillium Notes
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91021 is a stored cross-site scripting vulnerability in Trilium Notes (up to version 0.103.0) caused by improper neutralization of input during web page generation. Specifically, the share renderer for webView notes fails to properly escape user-controlled #webViewSrc values, enabling injection of arbitrary JavaScript code. An attacker with note-authoring privileges can exploit this to execute scripts in the context of other users viewing the shared note.
Potential Impact
An attacker with note-authoring privileges can inject malicious JavaScript that executes in the browsers of users who open the shared note, including administrators. This can lead to unauthorized actions performed on behalf of the victim, theft of sensitive information, or further compromise of user accounts. The vulnerability affects the confidentiality and integrity of user data within the application.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Users should exercise caution when sharing notes and restrict note-authoring privileges to trusted users only. Monitor the vendor's advisory channels for updates and apply any forthcoming patches promptly. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-09-14T17:02:03.736Z
- State
- PUBLISHED
Threat ID: 6aa8300355bf5e2cf5600a72
Added to database: 09/14/2026, 17:33:55 UTC
Last enriched: 09/14/2026, 17:46:54 UTC
Last updated: 09/15/2026, 07:20:15 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.