Cross-site scripting in Trix - CVE-2025-46812
Published: April 28, 2026
Trix
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to cross-site scripting in the Trix editor paste handling when processing pasted malicious code. A remote attacker can trick a user into copying and pasting crafted content to execute arbitrary JavaScript code.
User interaction is required to copy and paste the crafted content.