MEDIUM4.6npmRubyGems
GHSA-53g2-mvcc-q9x3· CVE-2026-73428Trix: Stored XSS via HTMLParser attribute injection on paste
Modified: 8/12/2026
package
pkg:rubygems/action_text-trix
Trix: Stored XSS via HTMLParser attribute injection on paste
Modified: 8/12/2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Modified: 9/10/2026
Trix has a stored XSS vulnerability through its attachment attribute
Modified: 9/10/2026
Trix has a Stored XSS vulnerability through serialized attributes
Modified: 9/10/2026