Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qmpg-8xg6-ph5q | Trix has a Stored XSS vulnerability through serialized attributes |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Basecamp
Basecamp trix |
|
| Vendors & Products |
Basecamp
Basecamp trix |
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17. | |
| Title | Trix: Stored XSS vulnerability through serialized attributes | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T17:47:02.477Z
Reserved: 2026-08-12T14:32:11.796Z
Link: CVE-2026-73426
No data.
Status : Received
Published: 2026-08-18T15:17:08.043
Modified: 2026-08-18T18:19:33.353
Link: CVE-2026-73426
No data.
OpenCVE Enrichment
Updated: 2026-08-18T17:30:15Z
Weaknesses
Github GHSA