Intel

AIKIDO-2024-10201

trix is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-43368

45

Medium Risk

This Affects:

JStrix
2.0.0 - 2.1.3
Fixed in 2.1.4

TL;DR

Affected versions of the package allow attackers to execute Cross-site Scripting (XSS) attacks by pasting malicious code into a Trix editor.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

trix is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.1.3.

How to fix this

Upgrade the trix library to the patch version.