Description
The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The HTMLParser processed a mock attachment, a <span> carrying an empty data-trix-attachment="{}".
Recommendation
Update the trix package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.18
- Patched version(s): 2.1.18
References
Could your website be exposed too?
SmartScanner can check your website for Trix: Stored XSS via HTMLParser attribute injection on paste and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check - CVE-2026-31860
- OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose") - CVE-2026-32308
- TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes - CVE-2026-55661
- Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers - CVE-2026-27902


