CVE-2026-91021: Trilium Trillium Notes

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators.

Affected products

  • Trilium Trillium Notes: up to and including v0.103.0

Published 2026-09-14. Last modified 2026-09-16.