Vulnerability library
Security checkAugust 12, 2026

Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Low severitynpmtrix

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when a crafted application/x-trix-document JSON payload is dropped into the editor in environments using the fallback Level0InputController (e.g., embedded WebViews lacking Input Events Level 2 support).

The StringPiece.fromJSON method trusted href attributes from the JSON payload without sanitization.

Recommendation

Update the trix package to the latest compatible version. Followings are version details:

  • Affected version(s): < 2.1.18
  • Patched version(s): 2.1.18

References

Could your website be exposed too?

SmartScanner can check your website for Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 12, 2026