View online: https://www.drupal.org/sa-contrib-2026-184 Project: Tawk.to - Live chat application [1] Project machine name: tawk_to Date: 2026-September-23 Security risk: *Critical* 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross Site Request Forgery Affected versions: <3.0.4 CVE IDs: CVE-2026-96388 Description: This module provides integration of the tawk.to live chat for Drupal sites. The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability. Solution: Install the latest version: * Upgrade to tawk.to 3.0.4 [3]. After updating, clear the Drupal cache. Reported By: * Tin Nguyen Huu (s4m0y3d) [4] Fixed By: * Andriy Khomych (andriy khomych) [5] * Tin Nguyen Huu (s4m0y3d) [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * Bram Driesen (bramdriesen) [8] of the Drupal Security Team * Damien McKenna (damienmckenna) [9] of the Drupal Security Team * Greg Knaddison (greggles) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [13] [1] https://www.drupal.org/project/tawk_to [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/tawk_to/releases/3.0.4 [4] https://www.drupal.org/u/s4m0y3d [5] https://www.drupal.org/u/andriy-khomych [6] https://www.drupal.org/u/s4m0y3d [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/bramdriesen [9] https://www.drupal.org/u/damienmckenna [10] https://www.drupal.org/u/greggles [11] https://www.drupal.org/u/poker10 [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....