Vulnerabilities/

Trix allows Cross-site Scripting via `javascript:` url in a link

Severity:
Medium

Description

The Trix editor, versions prior to 2.1.11, is vulnerable to XSS when pasting malicious code in the link field.

Recommendation

Update the trix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
trix
Anything's wrong? Let us know Last updated on January 03, 2025

This issue is available in SmartScanner Professional

See Pricing