Junglewise Threat Intelligence

CVE-2026-73426: Basecamp Trix Stored XSS in serialized attributes

CVE-2026-73426 · Severity: medium · CVSS 4.6 · Published 2026-03-12

Technologies: action_text-trix (RubyGems), trix (npm). Vendors: Basecamp, RubyGems, npm.

Executive brief

Trix, a popular rich text editor used in web applications, is vulnerable to a security flaw that allows attackers to inject malicious scripts into content. If a user views or interacts with this specially crafted content, the attacker's script could run in their browser, potentially allowing the attacker to steal session information or perform actions on the user's behalf. This issue affects applications using the Trix editor, including those integrated via the Ruby on Rails Action Text framework.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Trix versions prior to 2.1.17. The vulnerability stems from a bypass in the DOMPurify-based sanitization logic where the 'data-trix-serialized-attributes' attribute is not correctly stripped from untrusted input. During the serialization process, Trix treats the contents of this attribute as trusted instructions to create arbitrary DOM attributes using 'setAttribute()'. An attacker with the ability to provide HTML content (e.g., via pasting or saved comments) can include a malicious payload within this attribute to execute arbitrary JavaScript in the context of another user's session. The fix, introduced in version 2.1.17, adds a specific hook to DOMPurify to strip this attribute before it reaches the serialization sink.

Affected products

  • basecamp trix < 2.1.17
  • basecamp action_text-trix < 2.1.17

Timeline

  • 2026-03-11: patched: Version 2.1.17 released
  • 2026-03-12: advisory: GitHub Advisory published

References

Related threats