CVE-2026-73426: Basecamp Trix

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.

Affected products

  • Basecamp Trix: before 2.1.17 (fixed in 2.1.17)

Published 2026-08-18. Last modified 2026-09-18.