{"id":"CVE-2026-73428","title":"Trix is a what-you-see-is-what-you-get rich text editor for everyday writing","summary":"Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted into the editor. HTMLParser processes a mock attachment in a `<s…","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-79"],"published":"2026-08-13","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:09:01.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73428","references":[{"url":"https://github.com/basecamp/trix/commit/9c0a993d9fc2ffe9d56b013b030bc238f9c0557c","label":"security-advisories@github.com"},{"url":"https://github.com/basecamp/trix/pull/1293","label":"security-advisories@github.com"},{"url":"https://github.com/basecamp/trix/releases/tag/v2.1.18","label":"security-advisories@github.com"},{"url":"https://github.com/basecamp/trix/security/advisories/GHSA-53g2-mvcc-q9x3","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00203,"epssPercentile":0.10506,"ingestedAt":"2026-09-18T20:51:25.613Z","slug":"CVE-2026-73428","body":"## Overview\n\nTrix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted into the editor. HTMLParser processes a mock attachment in a `<span>` with an empty `data-trix-attachment=\"{}\"` value, causing data-trix-attributes to be applied to a plain string piece. StringPiece.fromJSON accepts an unvalidated href, allowing a javascript: URI to enter the document model and serialized HTML and execute when another user renders and clicks the content. Applications that apply server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}