What is CVE-2026-73428?
CVE-2026-73428 is a stored Cross-Site Scripting (XSS) vulnerability in the Trix rich text editor. It occurs when crafted HTML containing a mock attachment with an empty `data-trix-attachment` attribute is pasted into the editor, affecting versions prior to 2.1.18. Users should upgrade to version 2.1.18 or later immediately.
Azərbaycanca: CVE-2026-73428 Trix zəngin mətn redaktorunda saxlanılan Cross-Site Scripting (XSS) zəifliyidir. Bu zəiflik xüsusi hazırlanmış HTML məzmunun redaktora yapışdırılması zamanı meydana çıxır və 2.1.18 versiyasından əvvəlki versiyalara təsir edir. İstifadəçilər dərhal 2.1.18 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What product is affected by CVE-2026-73428?
CVE-2026-73428 affects the Trix rich text editor.
What version should users upgrade to in order to mitigate CVE-2026-73428?
Users should upgrade to Trix version 2.1.18 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.