Vulnerabilities/

Trix has a Stored XSS vulnerability through serialized attributes

Severity:
Medium

Description

The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer.

Recommendation

Update the trix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
trix
Anything's wrong? Let us know Last updated on March 18, 2026