๐Ÿ” CVE Alert

CVE-2026-73427

UNKNOWN 0.0

Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an embedded WebView without Input Events Level 2 support. The StringPiece.fromJSON method trusts href attributes from the JSON payload without sanitization, allowing a draggable element containing a javascript: URI to bypass DOMPurify sanitization and inject executable JavaScript into the DOM. Exploitation requires the victim to drag and drop attacker-controlled content, and server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18.

CWE CWE-79
Vendor basecamp
Product trix
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for basecamp trix

Be the first to know when new unknown vulnerabilities affecting basecamp trix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

basecamp / trix
< 2.1.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/basecamp/trix/security/advisories/GHSA-53p3-c7vp-4mcc github.com: https://github.com/basecamp/trix/pull/1293 github.com: https://github.com/basecamp/trix/commit/9c0a993d9fc2ffe9d56b013b030bc238f9c0557c github.com: https://github.com/basecamp/trix/releases/tag/v2.1.18