Cross-site scripting in Trix - #VU128364

 

Cross-site scripting in Trix - #VU128364

Published: April 28, 2026


Vulnerability identifier: #VU128364
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript code in the user's session.

The vulnerability exists due to cross-site scripting in the data-trix-serialized-attributes attribute handling when rendering crafted HTML content. A remote user can supply HTML containing a malicious data-trix-serialized-attributes attribute to execute arbitrary JavaScript code in the user's session.

User interaction is required when the content is rendered.


Affected software

Trix

Remediation

Install security update from vendor's website.

Trix - update to 2.1.17

External References

Related Security Bulletins