CVE-2026-73426 - Trix: Stored XSS vulnerability through serialized attributes
Brief
CVE ID : CVE-2026-73426
Published : Aug. 18, 2026, 2:24 p. m.
- 43 minutes ago
Description : Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.
- 17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer.
An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.
- 17.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
