Backport CVE-2025-21610 to v1 and update advisory
- Dominant language
- JavaScript
- Stars
- 20k
- Forks
- 1.1k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 13
Description
Hello,
as far as I know, Rails 7.0 is still in security support
is there by any chance the possibility to backport the fix for [CVE-2025-21610](https://github.com/basecamp/trix/security/advisories/GHSA-j386-3444-qgwg) to v1, release a new version, and update the advisory?
```
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ moderate │ Trix allows Cross-site Scripting via `javascript:` url in a │
│ │ link │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ trix │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=2.1.12 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ trix │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ trix │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1101430 │
└───────────────┴──────────────────────────────────────────────────────────────┘
```
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the linked CVE-2025-21610 advisory and the existing Trix v1 maintenance and release process. Done means the vulnerability fix is backported to v1, a new v1 version is released, and the advisory is updated to reflect that release.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100