Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103
View online: https://www.drupal.org/sa-contrib-2026-103 Project: Address Suggestion [1] Date: 2026-August-26 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross-site scripting Affected versions: <1.0.25 CVE IDs: CVE-2026-81167 Description: The Address Suggestion module provides address autocomplete functionality using configured address providers. The module doesn't sufficiently sanitize address suggestion data returned by configured providers, which can lead to a cross-site scripting (XSS) vulnerability. This vulnerability is mitigated by the fact that an attacker must be able to inject malicious content into data returned by a configured address provider, and a user must perform a search that returns the malicious suggestion. Solution: Install the latest version: * If you use the address_suggestion module, upgrade to address_suggestion 1.0.25 [3]. Reported By: * Conrad Lara (cmlara) [4] Fixed By: * Conrad Lara (cmlara) [5] * Joseph Olstad (joseph.olstad) [6] * NGUYEN Bao (lazzyvn) [7] Coordinated By: * Swan Kalata (akalata) [8] of the Drupal Security Team * Greg Knaddison (greggles) [9] of the Drupal Security Team * Jess (xjm) [10] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [11] [1] https://www.drupal.org/project/address_suggestion [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/address_suggestion/releases/1.0.25 [4] https://www.drupal.org/u/cmlara [5] https://www.drupal.org/u/cmlara [6] https://www.drupal.org/u/josepholstad [7] https://www.drupal.org/u/lazzyvn [8] https://www.drupal.org/u/akalata [9] https://www.drupal.org/u/greggles [10] https://www.drupal.org/u/xjm [11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org