Vulnerabilities/

Trix: Stored XSS via HTMLParser attribute injection on paste

Severity:
Medium

Description

The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The HTMLParser processed a mock attachment, a <span> carrying an empty data-trix-attachment="{}".

Recommendation

Update the trix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
trix
Anything's wrong? Let us know Last updated on August 12, 2026