Component blocks - Moderately critical - Cross site scripting - SA-CONTRIB-2026-123
View online: https://www.drupal.org/sa-contrib-2026-123 Project: Component blocks [1] Date: 2026-September-02 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross site scripting Affected versions: <1.2.7 CVE IDs: CVE-2026-84915 Description: This module enables you use UI Patterns with blocks, for use in Layout Builder. The module doesn't sufficiently validate user input before passing to token replacement. This vulnerability is mitigated by the fact that an attacker must have a role with the ability to edit layout builder layouts. Solution: Install the latest version: * If you use the component_blocks module, upgrade to Component Blocks 1.2.7 [3] Reported By: * Marcus Johansson (marcus_johansson) [4] Fixed By: * Lee Rowlands (larowlan) [5] of the Drupal Security Team Coordinated By: * Greg Knaddison (greggles) [6] of the Drupal Security Team * Lee Rowlands (larowlan) [7] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [8] [1] https://www.drupal.org/project/component_blocks [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/component_blocks/releases/1.2.7 [4] https://www.drupal.org/u/marcus_johansson [5] https://www.drupal.org/u/larowlan [6] https://www.drupal.org/u/greggles [7] https://www.drupal.org/u/larowlan [8] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org