View online: https://www.drupal.org/sa-contrib-2026-069 Project: Colorbox [1] Date: 2026-July-01 Security risk: *Moderately critical* 12 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Cross-site scripting Affected versions: < 2.1.5 || 2.2.0 CVE IDs: CVE-2026-58591 Description: The Colorbox module integrates with the Colorbox JavaScript library to display content in an overlay above the page. The module doesn't sufficiently protect against injection of malicious JavaScript under certain scenarios. This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content. Solution: Install the latest version: * If you use Colorbox 2.1.x, upgrade to: Colorbox 2.1.5 [3] * If you use Colorbox 2.2.x, upgrade to: Colorbox 2.2.1 [4] Reported By: * Pierre Rudloff (prudloff) [5] of the Drupal Security Team Fixed By: * Paul McKibben (paulmckibben) [6] Coordinated By: * Pierre Rudloff (prudloff) [7] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185155-colorbox-security/-/work_items/1 [8] ------------------------------------------------------------------------------ Contribution record [9] [1] https://www.drupal.org/project/colorbox [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/colorbox/releases/2.1.5 [4] https://www.drupal.org/project/colorbox/releases/2.2.1 [5] https://www.drupal.org/u/prudloff [6] https://www.drupal.org/u/paulmckibben [7] https://www.drupal.org/u/prudloff [8] https://git.drupalcode.org/security/185155-colorbox-security/-/work_items/1 [9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....