{"id":"CVE-2026-91021","title":"Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values","summary":"Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allow…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-116"],"vendor":"Trilium","product":"Trillium Notes","affected":["trillium_notes <= v0.103.0"],"published":"2026-09-14","updated":"2026-09-16","sourceUpdated":"2026-09-16T13:42:48.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91021","references":[{"url":"https://vokecyber.com/research/trilium-share-renderer-stored-xss","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"epss":0.0014,"epssPercentile":0.03751,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:41:10.009376Z"},"ingestedAt":"2026-09-14T18:12:17.309Z","slug":"CVE-2026-91021","body":"## Overview\n\nTrilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203316,"id":"CVE-2026-91021","ts":1789416907576,"field":"cvss","old":null,"new":"5.4"},{"seq":203315,"id":"CVE-2026-91021","ts":1789416907576,"field":"severity","old":"none","new":"medium"}]}