← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 14:24via CVEFeed

CVE-2026-73426 - Trix: Stored XSS vulnerability through serialized attributes

Brief

CVE ID : CVE-2026-73426

Published : Aug. 18, 2026, 2:24 p. m.

  • 43 minutes ago

Description : Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.

  • 17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer.

An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.

  • 17.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed