CVE-2025-46812

LOW

Trix <2.1.15 - XSS

Title source: llm
STIX 2.1

Description

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. This issue has been patched in version 2.1.15.

Scores

CVSS v4 2.0
EPSS 0.0035
EPSS Percentile 57.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
basecamp/trix < 2.1.15
npm/trix 0 - 2.1.15npm
Published May 08, 2025
Tracked Since Feb 18, 2026