Executive brief
Trix is a popular web-based rich text editor used in many applications to allow users to compose formatted content. The vulnerability allows an attacker to paste specially crafted HTML that executes malicious JavaScript when other users view or interact with the stored content. This is a stored (persistent) XSS attack that could compromise user sessions, steal credentials, or perform actions on behalf of affected users. Applications using server-side HTML sanitization are partially protected, but client-side rendering of unsanitized content is at risk.
Technical details
The vulnerability is a stored XSS (CWE-79) in Trix's HTMLParser and StringPiece deserialization. When processing pasted HTML, the parser encounters a mock attachment element (a <span> with empty data-trix-attachment="{}") that bypasses attachment handling and applies its data-trix-attributes to a plain string piece. The StringPiece.fromJSON method in versions prior to 2.1.18 accepted href values without validation, allowing attacker-supplied javascript: URIs to pass through unchanged into the document model. These URIs are then emitted verbatim in the serialized HTML output and execute when users click the link. The attack requires user interaction (pasting malicious content) but results in persistent XSS affecting all users viewing the content. The fix, released in version 2.1.18, adds sanitization to StringPiece.fromJSON to neutralize malicious URIs. Server-side HTML sanitization provides defense-in-depth protection.
Affected products
- Basecamp Trix < 2.1.18
- Basecamp action_text-trix < 2.1.18
Timeline
- 2026-07-24: disclosed: Vulnerability publicly disclosed via GitHub advisory GHSA-53g2-mvcc-q9x3
- 2026-03-26: patched: Fixed in Trix version 2.1.18 with StringPiece.fromJSON sanitization