Cross-Site Scripting Vulnerability in Trix Rich Text Editor by Basecamp
CVE-2026-73426

4.6MEDIUM

Key Information:

Vendor

Basecamp

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-73426?

The Trix rich text editor, used for creating rich text content, contains a vulnerability that allows an attacker to exploit a flaw in the handling of data-trix-serialized-attributes before version 2.1.17. By crafting malicious HTML with these attributes, an attacker can bypass the DOMPurify sanitizer, leading to the execution of arbitrary JavaScript in the user's session. This could result in unauthorized actions being performed or sensitive user information being disclosed, making it crucial for developers to upgrade to at least version 2.1.17 to mitigate these risks.

Affected Version(s)

trix < 2.1.17

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.