NIXPKGS-2026-0144
GitHub issue
published on 7 Feb 2026
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
Trilium Notes has a Timing Attack Vulnerability in /api/login/sync
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes byte-by-byte through statistical timing analysis. This enables complete authentication bypass without password knowledge, granting full read/write access to victim's knowledge base. This vulnerability is fixed in 0.101.0.
Affected products
Trilium
- ==< 0.101.0
Matching in nixpkgs
pkgs.trilium-server
Hierarchical note taking application with focus on building large personal knowledge bases
pkgs.trilium-desktop
Hierarchical note taking application with focus on building large personal knowledge bases
Package maintainers
-
@eliandoran Elian Doran <contact@eliandoran.me>
-
@FliegendeWurst Arne Keller <arne.keller@posteo.de>