CVE-2025-21610
Last modified
CVE-2025-21610 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javascript:` URL as a link that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. Users should upgrade to Trix editor version 2.1.12 or later to receive a patch. In addition to upgrading, affected users can disallow browsers that don't support a Content Security Policy (CSP) as a workaround for this and other cross-site scripting vulnerabilities. Set CSP policies such as script-src 'self' to ensure that only scripts hosted on the same origin are executed, and explicitly prohibit inline scripts using script-src-elem.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-21610?
How severe is CVE-2025-21610?
How do I fix CVE-2025-21610?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21605Redis is an open source, in-memory database that persists on…7.5
- CVE-2025-21606stats is a macOS system monitor in for the menu bar. The Sta…8.7
- CVE-2025-21607Vyper is a Pythonic Smart Contract Language for the EVM. Whe…7.5
- CVE-2025-21608Meshtastic is an open source mesh networking solution. In af…5.3
- CVE-2025-21609SiYuan is self-hosted, open source personal knowledge manage…9.1
- CVE-2025-2161Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected…6.1
- CVE-2025-21611tgstation-server is a production scale tool for BYOND server…8.8
- CVE-2025-21612TabberNeue is a MediaWiki extension that allows the wiki to …8.6
- CVE-2025-21613go-git is a highly extensible git implementation library wri…9.8
- CVE-2025-21614go-git is a highly extensible git implementation library wri…7.5
- CVE-2025-21615AAT (Another Activity Tracker) is a GPS-tracking application…5.5
- CVE-2025-21616Plane is an open-source project management tool. A cross-sit…5.4
Are you affected by CVE-2025-21610?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
