Intel

AIKIDO-2025-10299

trix is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-46812

49

Medium Risk

This Affects:

JStrix
0.9.0 - 2.1.14
Fixed in 2.1.15

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS). An attacker could trick users into pasting malicious code into the application, leading to the execution of arbitrary JavaScript in the context of the user's session. This could result in unauthorized actions or the exposure of sensitive information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

trix is vulnerable to Cross-site Scripting (XSS) in versions 0.9.0 - 2.1.14.

How to fix this

Upgrade the trix library to a patch version.