PT-2026-76587 · Trix · Trix

CVE-2026-73426

·

Published

2026-03-12

·

Updated

2026-08-18

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Trix versions prior to 2.1.17
Description Trix is a what-you-see-is-what-you-get rich text editor. The software is susceptible to cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites, when the data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing this attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session, potentially leading to unauthorized actions or the disclosure of sensitive information.
Recommendations Update to version 2.1.17 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73426
GHSA-QMPG-8XG6-PH5Q

Affected Products

Trix