Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-53p3-c7vp-4mcc | Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) |
Wed, 12 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Basecamp
Basecamp trix |
|
| Vendors & Products |
Basecamp
Basecamp trix |
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an embedded WebView without Input Events Level 2 support. The StringPiece.fromJSON method trusts href attributes from the JSON payload without sanitization, allowing a draggable element containing a javascript: URI to bypass DOMPurify sanitization and inject executable JavaScript into the DOM. Exploitation requires the victim to drag and drop attacker-controlled content, and server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18. | |
| Title | Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T20:50:17.434Z
Reserved: 2026-08-12T14:32:11.796Z
Link: CVE-2026-73427
No data.
Status : Received
Published: 2026-08-12T21:17:41.613
Modified: 2026-08-12T21:17:41.613
Link: CVE-2026-73427
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:30:10Z
Github GHSA