mediumCVSS 4.6Vulnerability

GHSA-qmpg-8xg6-ph5q

### Impact The Trix editor, in versions prior to 2.1.17, is vulnerable to XSS attacks when a `data-trix-serialized-attributes` attribute bypasses the DOMPurify sanitizer. An attacker could craft HTML containing a `data-trix-serialized-attributes` attribute with a malicious payload that, when the content is rendered, could execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. ### Patches Update Recommendation: Users should upgrade to Trix editor version 2.1.17 or later. ### References The XSS vulnerability was responsibly reported by Hackerone researcher [newbiefromcoma](https://hackerone.com/newbiefromcoma).

Properties

ghsa_id
GHSA-qmpg-8xg6-ph5q
severity
medium
summary
Trix has a Stored XSS vulnerability through serialized attributes
cvss_score
4.6
cve_id
GHSA-qmpg-8xg6-ph5q
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-03-12T17:29:30Z
source_url
https://github.com/advisories/GHSA-qmpg-8xg6-ph5q
ghsa_updated
2026-03-18T19:37:54Z

Related Entities (4)

AFFECTS (2)

[Software]rubygems/action_text-trix
[Software]npm/trix

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-qmpg-8xg6-ph5q (CVSS 4.6) — Ninja Signal Threat Intelligence | Ninja Signal