Description
The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer.
Recommendation
Update the trix package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.17
- Patched version(s): 2.1.17
References
Could your website be exposed too?
SmartScanner can check your website for Trix has a Stored XSS vulnerability through serialized attributes and gives you actionable findings to investigate.
Start a free scanRelated Issues
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- Trix has a stored XSS vulnerability through its attachment attribute - Vulnerability
- Pannellum has a XSS vulnerability in hot spot attributes - CVE-2026-27210
You might also like:
See something that needs correcting? Let us knowUpdated August 12, 2026


