Medium severity4.6NVD Advisory· Published Aug 18, 2026· Updated Sep 18, 2026
CVE-2026-73426
CVE-2026-73426
Description
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
action_text-trixRubyGems | < 2.1.17 | 2.1.17 |
trixnpm | < 2.1.17 | 2.1.17 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-qmpg-8xg6-ph5qghsaADVISORY
- github.com/basecamp/trix/commit/53197ab5a142e6b0b76127cb790726b274eaf1bcnvdWEB
- github.com/basecamp/trix/pull/1282nvdWEB
- github.com/basecamp/trix/releases/tag/v2.1.17nvdWEB
- github.com/basecamp/trix/security/advisories/GHSA-qmpg-8xg6-ph5qnvdWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/action_text-trix/GHSA-qmpg-8xg6-ph5q.ymlghsaWEB
- github.com/basecamp/trix/commit/3229c29c771ded4d247ed79b2ccd2cd05c4e74b4nvd
News mentions
0No linked articles in our index yet.