-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The core vulnerability exists in href attribute handling within the toolbar controller. The commit adds DOMPurify validation specifically for href attributes in setAttribute, introduces a data-trix-validate-href flag, and adds XSS-specific tests. The pre-patch code lacked proper validation of javascript: URIs in href attributes during link creation/editing, which is directly addressed by the added safeAttribute/isSafeAttribute checks using DOMPurify's validation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| trix | npm | < 2.1.12 | 2.1.12 |