Back

LOW

Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)

Published Aug 12, 2026

Description

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an embedded WebView without Input Events Level 2 support. The StringPiece.fromJSON method trusts href attributes from the JSON payload without sanitization, allowing a draggable element containing a javascript: URI to bypass DOMPurify sanitization and inject executable JavaScript into the DOM. Exploitation requires the victim to drag and drop attacker-controlled content, and server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18.

Affected products

Remediation

Red Hat statement

The version of action_text-trix shipped in Red Hat products is not affected by this vulnerability as it already includes the fix.

Red Hat mitigation

Upgrading to Trix 2.1.18+ resolves this issue. Applications using server-side HTML sanitization (such as Rails' built-in sanitizer) provide additional protection.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 13, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Deferred
Modified Sep 9, 2026
Red Hat
Severity Moderate
Public date Aug 12, 2026
GHSA-53P3-C7VP-4MCC