Cross-site scripting in Trix - #VU128364
Published: April 28, 2026
Trix
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript code in the user's session.
The vulnerability exists due to cross-site scripting in the data-trix-serialized-attributes attribute handling when rendering crafted HTML content. A remote user can supply HTML containing a malicious data-trix-serialized-attributes attribute to execute arbitrary JavaScript code in the user's session.
User interaction is required when the content is rendered.