Skip to content

Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)

Low severity GitHub Reviewed Published Mar 26, 2026 in basecamp/trix • Updated Apr 1, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts