Cross-Site Scripting Vulnerability in Trix Rich Text Editor by Basecamp
CVE-2026-73426
4.6MEDIUM
What is CVE-2026-73426?
The Trix rich text editor, used for creating rich text content, contains a vulnerability that allows an attacker to exploit a flaw in the handling of data-trix-serialized-attributes before version 2.1.17. By crafting malicious HTML with these attributes, an attacker can bypass the DOMPurify sanitizer, leading to the execution of arbitrary JavaScript in the user's session. This could result in unauthorized actions being performed or sensitive user information being disclosed, making it crucial for developers to upgrade to at least version 2.1.17 to mitigate these risks.
Affected Version(s)
trix < 2.1.17
