View online: https://www.drupal.org/sa-contrib-2026-178 Project: Project Browser [1] Project machine name: project_browser Date: 2026-September-23 Security risk: *Critical* 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross-site request forgery Affected versions: <2.0.3 || >=2.1.0 <2.1.5 CVE IDs: CVE-2026-96374 Description: The Project Browser module enables you to apply recipes and enable modules from the web user interface. The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF). Solution: Install the latest version: * If you use the 2.1.x branch, upgrade to Project Browser 2.1.5 [3]. * If you use the 2.0.x branch, upgrade to Project Browser 2.0.3 [4]. Reported By: * Tin Nguyen Huu (s4m0y3d) [5] Fixed By: * Chris Wells (chrisfromredfin) [6] * Tin Nguyen Huu (s4m0y3d) [7] Coordinated By: * Swan Kalata (akalata) [8] of the Drupal Security Team * Bram Driesen (bramdriesen) [9] of the Drupal Security Team * Greg Knaddison (greggles) [10] of the Drupal Security Team * Drew Webber (mcdruid) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [13] [1] https://www.drupal.org/project/project_browser [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/project_browser/releases/2.1.5 [4] https://www.drupal.org/project/project_browser/releases/2.0.3 [5] https://www.drupal.org/u/s4m0y3d [6] https://www.drupal.org/u/chrisfromredfin [7] https://www.drupal.org/u/s4m0y3d [8] https://www.drupal.org/u/akalata [9] https://www.drupal.org/u/bramdriesen [10] https://www.drupal.org/u/greggles [11] https://www.drupal.org/u/mcdruid [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....