We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent c6ce89c commit ee52390Copy full SHA for ee52390
1 file changed
advisories/github-reviewed/2026/03/GHSA-53p3-c7vp-4mcc/GHSA-53p3-c7vp-4mcc.json
@@ -1,7 +1,7 @@
1
{
2
"schema_version": "1.4.0",
3
"id": "GHSA-53p3-c7vp-4mcc",
4
- "modified": "2026-03-29T15:22:17Z",
+ "modified": "2026-04-01T17:07:32Z",
5
"published": "2026-03-29T15:22:17Z",
6
"aliases": [],
7
"summary": "Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)",
@@ -68,6 +68,10 @@
68
69
"type": "WEB",
70
"url": "https://github.com/basecamp/trix/releases/tag/v2.1.18"
71
+ },
72
+ {
73
+ "type": "WEB",
74
+ "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/action_text-trix/GHSA-53p3-c7vp-4mcc.yml"
75
}
76
],
77
"database_specific": {
0 commit comments