Back

MEDIUM

Trix: Stored XSS vulnerability through serialized attributes

Published Aug 18, 2026

Description

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 18, 2026
Updated Aug 18, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Aug 18, 2026
NVD
Status Deferred
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-QMPG-8XG6-PH5Q