Wiki
TriliumNext/Trilium
Build your personal knowledge base with Trilium Notes
#knowledge-graph#note-taking#notebook#knowledge-base#knowledge-management#knowledge-management-graph#electron#electron-app#local-first#self-hosted#self-hosting#personal-knowledge-base#personal-wiki#wiki#note-managment#note-taker#notes#notes-app#scriptable
スコア
85
/ 100
Star
36,062
Fork
2,404
Open Issue
723
サイズ
545MB
言語
TypeScript ★
最終push
0 日前
Docker
🐳 compose ★
採点内訳
過去CVE 7件 (適量)
✓直近 push: 0 日前
✓得意言語 (TypeScript)
✓オープンissue 723件
✓超大規模 (0.5GB)
—Docker 対応 (compose)
✓10k–50k: 中級 (★36,062)
—※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (14 件)
- Stored XSS via unescaped shareExternalLink label in share index page
- SQL Injection via Unsanitized URL Parameter in `getDayNotesForMonth`
- Note Import to RCE via #docName Path Traversal (Safe Import Enabled)
- Local File Inclusion in upload modified file API endpoint
- TCC Bypass via Prompt Spoofing
- Note Import to RCE via AI/LLM Chat Stored XSS (Safe Import Enabled)
- Authentication Bypass in Clipper API for Electron (Desktop) Builds
- Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments
- Remote code execution via malicious note
- Stored XSS via unsanitized SVG in share system
- Stored XSS in calendar recurrence error toast via #recurrence label value leads to RCE in synchronized Electron desktop clients
- OAuth State Uses Weak Random Number Generator
- Timing Attack Vulnerability in /api/login/sync (CWE-208)
- Brute-force Protection Bypass via Initial Sync Seed Retrieval