High severity7.4NVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026
CVE-2025-68621
CVE-2025-68621
Description
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes byte-by-byte through statistical timing analysis. This enables complete authentication bypass without password knowledge, granting full read/write access to victim's knowledge base. This vulnerability is fixed in 0.101.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <0.101.0
<0.101.0+ 1 more
- (no CPE)range: <0.101.0
- (no CPE)range: < 0.101.0
Patches
Vulnerability mechanics
References
2- github.com/TriliumNext/Trilium/pull/8129nvdIssue TrackingPatch
- github.com/TriliumNext/Trilium/security/advisories/GHSA-hxf6-58cx-qq3xnvdExploitMitigationPatchVendor Advisory
News mentions
0No linked articles in our index yet.