๐Ÿ” CVE Alert

CVE-2026-73426

MEDIUM 4.6

Trix: Stored XSS vulnerability through serialized attributes

CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
0th

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.

CWE CWE-79
Vendor basecamp
Product trix
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for basecamp trix

Be the first to know when new medium vulnerabilities affecting basecamp trix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

basecamp / trix
< 2.1.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/basecamp/trix/security/advisories/GHSA-qmpg-8xg6-ph5q github.com: https://github.com/basecamp/trix/pull/1282 github.com: https://github.com/basecamp/trix/commit/3229c29c771ded4d247ed79b2ccd2cd05c4e74b4 github.com: https://github.com/basecamp/trix/commit/53197ab5a142e6b0b76127cb790726b274eaf1bc github.com: https://github.com/basecamp/trix/releases/tag/v2.1.17