View online: https://www.drupal.org/sa-contrib-2026-038 Project: Drupal AlternativeCommerce (Basket) [1] Date: 2026-May-27 Security risk: *Highly critical* 22 ∕ 25 AC:None/A:None/CI:All/II:All/E:Theoretical/TD:All [2] Vulnerability: Arbitrary PHP code execution Affected versions: <2.1.17 CVE IDs: CVE-2026-9726 Description: The Basket module enables e-commerce and checkout functionality for Drupal sites. The module does not sufficiently sanitize user-supplied data before passing it to PHP's unserialize(). An attacker can supply a crafted payload and trigger PHP Object Injection. If a viable gadget chain exists in the site codebase or installed dependencies, this can result in arbitrary PHP code execution. Solution: Install the latest version: * If you use the Basket module, upgrade to Basket 2.1.17. Reported By: * Drew Webber (mcdruid) [3] of the Drupal Security Team Fixed By: * Helena Zajika (helena zajika) [4] * Drew Webber (mcdruid) [5] of the Drupal Security Team Coordinated By: * Greg Knaddison (greggles) [6] of the Drupal Security Team * Dave Long (longwave) [7] of the Drupal Security Team * Drew Webber (mcdruid) [8] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185185-basket-security/-/work_items/1 [9] ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/basket [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/u/mcdruid [4] https://www.drupal.org/u/helena-zajika [5] https://www.drupal.org/u/mcdruid [6] https://www.drupal.org/u/greggles [7] https://www.drupal.org/u/longwave [8] https://www.drupal.org/u/mcdruid [9] https://git.drupalcode.org/security/185185-basket-security/-/work_items/1 [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....