action_text-trix
RubyGems2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting action_text-trixpage 1 of 1
- CVE-2026-73427LOWCVSS 2.1EG 2.1✓ Fixed in 2.1.182026-08-12
vulnerable: 0.0.1, 2.1.15, 2.1.16, 2.1.17
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback …
- CVE-2026-73428MEDIUMCVSS 4.6EG 4.6✓ Fixed in 2.1.182026-07-24
vulnerable: 0.0.1, 2.1.15, 2.1.16, 2.1.17
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted into the editor. HTMLParser processes a mock attachment in a `<spa…
Check whether action_text-trix is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for action_text-trix CVEs against the assets you own.
Start Free Scan →