A vulnerability has been found in Basecamp Trix up to 2.1.17 and classified as problematic. The affected element is the function
StringPiece.fromJSON of the component HTMLParser/StringPiece. The manipulation leads to HTML injection.
This vulnerability is referenced as CVE-2026-73428. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.