---
id: CVE-2026-77438
title: Trilium is an open-source hierarchical note-taking application
summary: >-
  Trilium is an open-source hierarchical note-taking application. In versions up
  to and including 0.103.0, the public share-search endpoint does not enforce
  the per-note shareCredentials and shareHiddenFromTree controls, allowing an
  unauth…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-863
published: '2026-08-27'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:49:20.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77438'
references:
  - url: >-
      https://github.com/TriliumNext/Trilium/commit/49fc7b67d9d49f01833e1ad9712ec83b079f98d2
    label: security-advisories@github.com
  - url: >-
      https://github.com/TriliumNext/Trilium/security/advisories/GHSA-6rxv-6w3q-7mv9
    label: security-advisories@github.com
  - url: >-
      https://github.com/TriliumNext/Trilium/security/advisories/GHSA-6rxv-6w3q-7mv9
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.15575
ingestedAt: '2026-09-09T17:16:03.070Z'
---

## Overview

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and then runs a full-text search across the entire published subtree, returning each matching note's title, share identifier, and hierarchical path without re-checking whether that individual note requires a share password or is hidden from the navigation tree. Because the search matches note content, an attacker can enumerate protected notes and use the endpoint as a boolean oracle that confirms arbitrary substrings, recovering the full contents of notes that should be gated behind a password. This issue is fixed in version 0.104.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
