action_text-trix
A rich text editor for everyday writing
Activity
- Latest release
- 4mo ago
- Total releases
- 6
- Cadence
- ~43 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- MIT
- First release
- May 12, 2025
| Version | Released | |
|---|---|---|
2.1.19
patch
| ||
2.1.18
patch
| ||
2.1.17
patch
2 CVEs
CVE-2026-73428
GHSA-53g2-mvcc-q9x3
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The This is a stored XSS in any application that accepts untrusted rich text through Trix and renders the serialized output to other users. Applications that apply server-side HTML sanitization, such as the Rails built-in sanitizer, are additionally protected because the payload is neutralized on save. This vulnerability shares its fix with GHSA-53p3-c7vp-4mcc. Both are resolved by the PatchesUsers should upgrade to Trix editor version 2.1.18 or later. ReferencesThe vulnerability was responsibly reported by HackerOne researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-73427
GHSA-53p3-c7vp-4mcc
Mar 29, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
Network
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when a crafted The Exploitation requires a specific environment (Level0InputController fallback) and social engineering (victim must drag and drop attacker-controlled content into the editor). Applications using server-side HTML sanitization (such as Rails' built-in sanitizer) are additionally protected, as the payload is neutralized on save. PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.18 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.16
patch
3 CVEs
CVE-2026-73428
GHSA-53g2-mvcc-q9x3
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The This is a stored XSS in any application that accepts untrusted rich text through Trix and renders the serialized output to other users. Applications that apply server-side HTML sanitization, such as the Rails built-in sanitizer, are additionally protected because the payload is neutralized on save. This vulnerability shares its fix with GHSA-53p3-c7vp-4mcc. Both are resolved by the PatchesUsers should upgrade to Trix editor version 2.1.18 or later. ReferencesThe vulnerability was responsibly reported by HackerOne researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-73427
GHSA-53p3-c7vp-4mcc
Mar 29, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
Network
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when a crafted The Exploitation requires a specific environment (Level0InputController fallback) and social engineering (victim must drag and drop attacker-controlled content into the editor). Applications using server-side HTML sanitization (such as Rails' built-in sanitizer) are additionally protected, as the payload is neutralized on save. PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.18 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73426
GHSA-qmpg-8xg6-ph5q
Mar 12, 2026
Trix has a Stored XSS vulnerability through serialized attributes
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a An attacker could craft HTML containing a PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.17 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
Fixed in
2.1.17
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.15
major
4 CVEs
CVE-2026-73428
GHSA-53g2-mvcc-q9x3
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The This is a stored XSS in any application that accepts untrusted rich text through Trix and renders the serialized output to other users. Applications that apply server-side HTML sanitization, such as the Rails built-in sanitizer, are additionally protected because the payload is neutralized on save. This vulnerability shares its fix with GHSA-53p3-c7vp-4mcc. Both are resolved by the PatchesUsers should upgrade to Trix editor version 2.1.18 or later. ReferencesThe vulnerability was responsibly reported by HackerOne researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-73427
GHSA-53p3-c7vp-4mcc
Mar 29, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
Network
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when a crafted The Exploitation requires a specific environment (Level0InputController fallback) and social engineering (victim must drag and drop attacker-controlled content into the editor). Applications using server-side HTML sanitization (such as Rails' built-in sanitizer) are additionally protected, as the payload is neutralized on save. PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.18 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73426
GHSA-qmpg-8xg6-ph5q
Mar 12, 2026
Trix has a Stored XSS vulnerability through serialized attributes
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a An attacker could craft HTML containing a PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.17 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
Fixed in
2.1.17
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-g9jg-w8vm-g96v
Dec 31, 2025
Trix has a stored XSS vulnerability through its attachment attribute
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.16, is vulnerable to XSS attacks through attachment payloads. An attacker could inject malicious code into a data-trix-attachment attribute that, when rendered as HTML and clicked on, could execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.16 or later. ResourcesThe XSS vulnerability was reported by HackerOne researcher michaelcheers. Affected versions
0.0.1
2.1.15
Fixed in
2.1.16
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.0.1
initial
4 CVEs
CVE-2026-73428
GHSA-53g2-mvcc-q9x3
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The This is a stored XSS in any application that accepts untrusted rich text through Trix and renders the serialized output to other users. Applications that apply server-side HTML sanitization, such as the Rails built-in sanitizer, are additionally protected because the payload is neutralized on save. This vulnerability shares its fix with GHSA-53p3-c7vp-4mcc. Both are resolved by the PatchesUsers should upgrade to Trix editor version 2.1.18 or later. ReferencesThe vulnerability was responsibly reported by HackerOne researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-73427
GHSA-53p3-c7vp-4mcc
Mar 29, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
Network
Low
None
ImpactThe Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when a crafted The Exploitation requires a specific environment (Level0InputController fallback) and social engineering (victim must drag and drop attacker-controlled content into the editor). Applications using server-side HTML sanitization (such as Rails' built-in sanitizer) are additionally protected, as the payload is neutralized on save. PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.18 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
2.1.17
Fixed in
2.1.18
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73426
GHSA-qmpg-8xg6-ph5q
Mar 12, 2026
Trix has a Stored XSS vulnerability through serialized attributes
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a An attacker could craft HTML containing a PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.17 or later. ReferencesThe XSS vulnerability was responsibly reported by Hackerone researcher newbiefromcoma. Affected versions
0.0.1
2.1.15
2.1.16
Fixed in
2.1.17
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-g9jg-w8vm-g96v
Dec 31, 2025
Trix has a stored XSS vulnerability through its attachment attribute
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactThe Trix editor, in versions prior to 2.1.16, is vulnerable to XSS attacks through attachment payloads. An attacker could inject malicious code into a data-trix-attachment attribute that, when rendered as HTML and clicked on, could execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. PatchesUpdate Recommendation: Users should upgrade to Trix editor version 2.1.16 or later. ResourcesThe XSS vulnerability was reported by HackerOne researcher michaelcheers. Affected versions
0.0.1
2.1.15
Fixed in
2.1.16
References
Updated Sep 10, 2026 · Source: OSV.dev |