Vulnerabilities/

Trix editor subject to XSS vulnerabilities on copy & paste

Severity:
Medium

Description

The Trix editor, in versions prior to 2.1.9 and 1.3.3, is vulnerable to XSS + mutation XSS attacks when pasting malicious code.

Recommendation

Update the trix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
trix
Anything's wrong? Let us know Last updated on December 09, 2024

This issue is available in SmartScanner Professional

See Pricing