basecamp / basecamp/trix

Backport CVE-2025-21610 to v1 and update advisory

Open
#1,223 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
20k
Forks
1.1k
Avg merge
3d 12h
Merged PRs (30d)
13

Description

Hello,

as far as I know, Rails 7.0 is still in security support

is there by any chance the possibility to backport the fix for [CVE-2025-21610](https://github.com/basecamp/trix/security/advisories/GHSA-j386-3444-qgwg) to v1, release a new version, and update the advisory?

```
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ moderate │ Trix allows Cross-site Scripting via `javascript:` url in a │
│ │ link │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ trix │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=2.1.12 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ trix │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ trix │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1101430 │
└───────────────┴──────────────────────────────────────────────────────────────┘
```

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the linked CVE-2025-21610 advisory and the existing Trix v1 maintenance and release process. Done means the vulnerability fix is backported to v1, a new v1 version is released, and the advisory is updated to reflect that release.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.