Drupal Contrib Security
Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069
The Colorbox module integrates with the Colorbox JavaScript library to display content in an overlay above the page.
The module doesn't sufficiently protect against injection of malicious JavaScript under certain scenarios.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.
Solution:Install the latest version:
- If you use Colorbox 2.1.x, upgrade to: Colorbox 2.1.5
- If you use Colorbox 2.2.x, upgrade to: Colorbox 2.2.1
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
This module enables you to test and run AI-driven workflows interactively through a chat interface.
The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions).
Solution:Install the latest version:
- If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0
- Greg Knaddison (greggles) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
This module enables you to test and run AI-driven workflows interactively through a chat interface.
The module doesn't sufficiently enforce permissions on certain endpoints. Attackers may be able to trigger workflow execution (incurring LLM spend and tool side effects) or send messages into other user's sessions.
This vulnerability is mitigated by the fact that an attacker must have the permission "View any session", which is not granted to anonymous or authenticated users by default.
Solution:Install the latest version:
- If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0
Driving a session now additionally requires the "Execute session workflow" permission.
Reported By: Fixed By: Coordinated By:- Greg Knaddison (greggles) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066
The Canvas module allow you to upload image files via a custom API.
The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious user to upload a file that is not an image.
Certain web-server configurations may serve the uploaded file with its actual MIME type rather than an image type. This may lead to cross-site scripting (XSS) or other unexpected behavior.
Solution:Install the latest version:
- If you use the 1.4.1 version of Canvas, upgrade to 1.4.2
- If you use the 1.5.1 version of Canvas, upgrade to 1.5.2
- If you use the 1.6.0 version of Canvas, upgrade to 1.6.1
- If you use the 1.7.0 version of Canvas, upgrade to 1.7.1
- Juraj Nemec (poker10) of the Drupal Security Team
Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065
The Canvas AI submodule allows you to upload image files via a custom API to use within the AI web chat.
These file uploads are insufficiently validated before being written to Drupal's temporary directory. In some cases, this may lead to cross-site scripting (XSS).
Solution:Install the latest version:
- If you use the 1.4.1 version of Canvas, upgrade to 1.4.2
- If you use the 1.5.1 version of Canvas, upgrade to 1.5.2
- If you use the 1.6.0 version of Canvas, upgrade to 1.6.1
- If you use the 1.7.0 version of Canvas, upgrade to 1.7.1
- Alex Bronstein (effulgentsia) of the Drupal Security Team
- Christian López Espínola (penyaskito)
- Juraj Nemec (poker10) of the Drupal Security Team
Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064
The Tealium iQ Tag Management module provides Drupal integration with Tealium iQ.
tealiumiq stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an Object Injection vulnerability when the data are unserialized.
This vulnerability is mitigated by the fact that an attacker must have permission to edit a content entity with an attached tealiumiq field. In addition, the core jsonapi module must be enabled with the option "Accept all JSON:API create, read, update, and delete operations", which is not the default, or the attacker needs some other way to edit field values directly.
Note: This project was marked as Unsupported by the Drupal Security Team on 2026-06-24 but a fix was released and the project restored on 2026-06-26.
Solution:Install the latest version:
- If you use the Tealium iQ Tag Management module, upgrade to Tealium iQ Tag Management 8.x.2.4
- Drew Webber (mcdruid) of the Drupal Security Team
- Benji Fisher (benjifisher) of the Drupal Security Team
- Daniel Schiavone (schiavone)
- Benji Fisher (benjifisher) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063
The Salesforce Suite of modules integrates Drupal with Salesforce.
The Salesforce module does not properly validate the OAuth handshake during interactive authentication, allowing an attacker to hijack the authorization token and bind the site to an attacker's Salesforce account.
This vulnerability is mitigated by the fact that salesforce_oauth submodule must be enabled, and a salesforce_oauth authorization profile active and in use. The submodule salesforce_oauth is deprecated, and salesforce_jwt has been the recommended authentication plugin for several years. Sites with salesforce_oauth uninstalled, or sites relying exclusively on salesforce_jwt (JWT or JWT Gov Cloud) for authentication are not impacted.
Submodule salesforce_oauth has been removed in branch 6.0.x, so >= 6.0.x versions are not affected by this vulnerability.
Solution:Recommended solution:
- Update to Salesforce Suite version 5.1.3
- Uninstall salesforce_oauth module
Alternative solution, if you must continue to use salesforce_oauth module:
- Update to Salesforce Suite version 5.1.3
- Revoke existing oauth provider tokens
- Re-authenticate all existing oauth providers
- Neil Drumm (drumm) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
Geolocation modules adds a field to store coordinates and provides supporting plumbing for views and other modules.
One of the provided views filters does not sufficiently sanitize values if exposed to user input resulting in a SQL injection vulnerability.
This vulnerability is mitigated by the fact that a view must exist, that uses the aforementioned filter and it is set to accept user input.
Solution:Install the latest version:
- If you use the Geolocation Field module for Drupal, upgrade to Geolocation Field 8.x-3.15
- cilefen (cilefen) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to direct child paragraphs of library items through API endpoints.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use and general write access to paragraphs through another module must be allowed.
Install the latest version:
- If you use the Paragraphs module for Drupal 8.x, upgrade to Paragraphs 8.x-1.21
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to unpublished library items in lists.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use, and that an attacker must have access to a list of library items, such as a field with autocomplete suggestions or a view.
Install the latest version:
- If you use the Paragraphs module for Drupal 8.x, upgrade to Paragraphs 8.x-1.21
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Sascha Grossenbacher (berdir)
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
WissKI - Critical - Access bypass - SA-CONTRIB-2026-059
The module adds support for the mirador viewer in WissKI and enables annotations on images via the mirador viewer.
It does not sufficiently check the submitted parameters via a route and writes these to the session object without further checks, which can lead to Access Bypass.
This vulnerability is mitigated by the fact that it is specific to the wisski_mirador submodule.
Solution:Install the latest version:
- If you use the WissKI module version 8.x-4.1, upgrade to WissKI 8.x-4.2
- Drew Webber (mcdruid) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058
This module enables you to take payments through the Global Payments / Realex Hosted Payment Page (HPP), either via a lightbox iframe or via a full-page redirect.
When the gateway is configured with the redirect payment method, the module doesn't sufficiently verify the authenticity of the payment response returned by Global Payments.
The lightbox payment method validates the signature and is not affected, so sites that use the lightbox payment method are not affected.
Solution:Install the latest version:
- If you use the commerce_realex module <=3.0.1, upgrade to commerce_realex 3.0.2.
The redirect payment response is now cryptographically verified against the merchant shared secret .
Sites that cannot update immediately should disable this payment gateway, until the update can be applied.
Reported By: Fixed By: Coordinated By:- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057
This module provides the entity type and runtime for Drupal AI Agents, enabling agents to use tools.
Under certain circumstances, the agent inherits deterministic parameters when invoking the same tool in one request, which can lead to information disclosure.
Solution:Install the latest version:
- If you use the AI Agents module 1.1.3, upgrade to AI Agents 1.1.4
- If you use the AI Agents module 1.2.4 upgrade to AI Agents 1.2.5
- If you use the AI Agents module 1.3.0 upgrade to AI Agents 1.3.1
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
This module provides the entity type and runtime for Drupal AI Agents, enabling agents to use tools.
The module does not sufficiently check the required permissions when a tool loads content entities.
This vulnerability is mitigated by the fact that an agent must be configured to use the affected tool, and an attacker must have access to that agent.
Solution:Install the latest version:
- If you use the AI Agents module 1.1.3, upgrade to AI Agents 1.1.4
- If you use the AI Agents module 1.2.4 upgrade to AI Agents 1.2.5
- If you use the AI Agents module 1.3.0 upgrade to AI Agents 1.3.1
- Artem Dmitriiev (a.dmitriiev)
- AKHIL BABU (akhil babu)
- harivansh sharma (harivansh)
- Kuniyoshi Noguchi (kuninogu)
- Marcus Johansson (marcus_johansson)
- Bram Driesen (bramdriesen) of the Drupal Security Team
AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
This module enables you to utilize an agent to use Drupal core actions tools with bypassed access.
Certain Drupal core actions, exposed as agent tools did not have correct access validation, and some core actions were missing associated access-level definitions.
This vulnerability is mitigated by the fact that an attacker must have access to communicate with an affected agent, the site must be configured to expose the affected tools to non-privileged users.
Solution:Install the latest version:
- If you use the AI module 1.2.16, upgrade to AI 1.2.17
- If you use the AI module 1.3.7 upgrade to AI 1.3.8
- If you use the AI module 1.4.2 upgrade to AI 1.4.3
- Artem Dmitriiev (a.dmitriiev)
- Marcus Johansson (marcus_johansson)
- Dezső Biczó (mxr576)
- Valery Lourie (valthebald)
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054
The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM to generate HTML or Markdown and preview it in a browser.
Under certain circumstances, rendering of this HTML can lead to Cross Site Scripting, or exposing secret communications in the context of the LLM request.
This vulnerability is mitigated by the fact that an attacker must be able to inject text into prompts to create an attack.
Solution:Install the latest version:
- If you use the AI module 1.2.16, upgrade to AI 1.2.17
- If you use the AI module 1.3.7 upgrade to AI 1.3.8
- If you use the AI module 1.4.2 upgrade to AI 1.4.3
- Drew Webber (mcdruid) of the Drupal Security Team
- Artem Dmitriiev (a.dmitriiev)
- Abhisek Mazumdar (abhisekmazumdar)
- AKHIL BABU (akhil babu)
- Marcus Johansson (marcus_johansson)
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
This module enables you to use OpenAI as a provider for the AI module.
The module doesn't sufficiently sanitize user-supplied URLs, leading to a Server-side request forgery (SSRF) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have the access to change the host url and a way to generate AI-generated images.
Solution:Install the latest version:
- If you use the OpenAI Provider module 1.1.0, upgrade to OpenAI Provider 1.1.1
- If you use the OpenAI module 1.2.1 upgrade to OpenAI Provider 1.2.2
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052
This module enables you to collect feedback from your site visitors on content pages, allowing them to optionally attach a free-text comment to their Yes/No vote.
The module doesn't sufficiently verify authorization over the targeted feedback record when processing a comment submission.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "give feedback". Note: "give feedback" is granted to anonymous and authenticated by default on install.
Solution:Install the latest release:
- If you use the admin_feedback module for Drupal 8.x, upgrade to admin_feedback 8.x-2.8
The comment endpoint now requires an HMAC-signed token bound to the specific feedback row (issued only to the visitor who cast that vote), and a comment may be written only once, preventing both forgery of arbitrary ids and replay.
Reported By: Fixed By: Coordinated By:- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051
This module enables you to collect feedback from your site visitors on content pages, presenting Yes/No buttons and providing dashboards for administrators to review the responses.
The module doesn't sufficiently sanitize several administrator-configured response messages (the "Yes response", "No response", and the custom text shown on a "No" answer) under the scenario where those settings contain HTML or script markup, which is then emitted as raw HTML in the feedback response shown to visitors.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer admin feedback".
Solution:Install the latest release:
- If you use the admin_feedback module for Drupal 8.x, upgrade to admin_feedback 8.x-2.8
The configured plain-text responses are now escaped with `Html::escape()`, and the formatted "No" response is rendered through its configured text format filter (`check_markup()`) instead of being printed raw.
Reported By: Fixed By: Coordinated By:- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
The Plotly.js Graphing module provides a fully customizable implementation of the open source Plotly.js graphing library.
The module stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an object injection vulnerability when the data are unserialized.
This vulnerability is mitigated by the fact that an attacker must have permission to edit a content entity with an attached plotly_js_graph field. In addition, the core JSON:API module must be enabled with the option "Accept all JSON:API create, read, update, and delete operations", which is not the default, or the attacker needs some other way to edit field values directly.
Solution:Install the latest version:
- If you use the Plotly.js Graphing module for Drupal, upgrade to plotly_js-3.0.2.
- Drew Webber (mcdruid) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team

Neue Kommentare
vor 2 Wochen 3 Tagen
vor 2 Wochen 6 Tagen
vor 3 Wochen 23 Stunden
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 6 Tagen
vor 4 Wochen 13 Stunden
vor 4 Wochen 21 Stunden