CVE-2025-68621

HIGH

Trilium Notes <0.101.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-68621. PoCs published by sivaadityacoder.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2025-68621, a timing attack vulnerability in Trilium Notes' sync authentication endpoint. The PoC recovers the HMAC hash one byte at a time using statistical timing analysis.

Description

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes byte-by-byte through statistical timing analysis. This enables complete authentication bypass without password knowledge, granting full read/write access to victim's knowledge base. This vulnerability is fixed in 0.101.0.

Exploits (1)

github WORKING POC
by sivaadityacoder · pythonpoc
https://github.com/sivaadityacoder/CVE-2025-68621

This repository contains a functional proof-of-concept exploit for CVE-2025-68621, a timing attack vulnerability in Trilium Notes' sync authentication endpoint. The PoC recovers the HMAC hash one byte at a time using statistical timing analysis.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Complex
Reliability
Reliable
Target: Trilium Notes < 0.101.0
No auth needed
Prerequisites: network access to the target server · ability to send thousands of HTTP requests · low network jitter
devstral-2 · analyzed Apr 25, 2026 Full analysis →

References (2)

Core 2
Core References
Issue Tracking x_refsource_misc
https://github.com/TriliumNext/Trilium/pull/8129

Scores

CVSS v3 7.4
EPSS 0.0051
EPSS Percentile 39.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-208
Status published
Products (1)
triliumnotes/trilium < 0.101.0
Published Feb 06, 2026
Tracked Since Feb 18, 2026