CVE-2025-53544 Details
Description
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection bypass in the initial sync seed retrieval endpoint allows unauthenticated attackers to guess the login password without triggering rate limiting. Trilium is a single-user app without a username requirement, and brute-force protection bypass makes exploitation much more feasible. Multiple features provided by Trilium (e.g. MFA, share notes, custom request handler) indicate that Trilium can be exposed to the internet. This is fixed in version 0.97.0.
A brute-force protection bypass vulnerability has been identified in Trilium Notes versions prior to 0.97.0. This issue allows unauthenticated attackers to guess login passwords through the initial sync seed retrieval endpoint, bypassing rate limiting measures. Trilium Notes is a single-user application that does not require a username, making this vulnerability particularly concerning. The lack of a strong password policy further exacerbates the issue, as passwords can be very simple. Additionally, features like multi-factor authentication and note sharing suggest that Trilium can be exposed to the internet.
Users are advised to upgrade to Trilium Notes version 0.97.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2025CISA-ADP
Assessed Aug 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TriliumNext/Trilium/security/advisories/GHSA-hw5p-ff75-327r | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/TriliumNext/Trilium/pull/6243/commits/04c8f8a1234e8c9f4a87da187180375227b21223 | [email protected] | Source CodeVendor |
| https://github.com/TriliumNext/Trilium/releases/tag/v0.97.0 | [email protected] | Release NotesVendor |
| https://github.com/TriliumNext/Trilium/security/advisories/GHSA-hw5p-ff75-327r | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Trilium | <= 0.96.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | New CVE Received | [email protected] |
Volerion