Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
View online: https://www.drupal.org/sa-core-2026-012 Project: Drupal core [1] Date: 2026-July-14 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Cross-site scripting Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.* CVE IDs: CVE-2026-55805 Description: The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability. This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface. Solution: Install the latest version: *Drupal 11* * If you use Drupal 11.4.x, update to Drupal 11.4.4 [3]. * If you use Drupal 11.3.x, update to Drupal 11.3.14 [4]. * Drupal 11.2.x and below are end-of-life and do not receive security coverage. *Drupal 10* * If you use Drupal 10.6.x, update to Drupal 10.6.13 [5]. * Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 [6] and Drupal 9 [7] have both reached end-of-life. Reported By: * haii haii (hai27ii2o) [8] Fixed By: * danielveza [9] * Lee Rowlands (larowlan) [10] of the Drupal Security Team * Mingsong (mingsong) [11] provisional member of the Drupal Security Team * James Gilliland (neclimdul) [12] of the Drupal Security Team Coordinated By: * Greg Knaddison (greggles) [13] of the Drupal Security Team * Lee Rowlands (larowlan) [14] of the Drupal Security Team * Dave Long (longwave) [15] of the Drupal Security Team * Jess (xjm) [16] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [17] [1] https://www.drupal.org/project/drupal [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/drupal/releases/11.4.4 [4] https://www.drupal.org/project/drupal/releases/11.3.14 [5] https://www.drupal.org/project/drupal/releases/10.6.13 [6] https://www.drupal.org/psa-2021-06-29 [7] https://www.drupal.org/psa-2023-11-01 [8] https://www.drupal.org/u/hai27ii2o [9] https://www.drupal.org/u/danielveza [10] https://www.drupal.org/u/larowlan [11] https://www.drupal.org/u/mingsong [12] https://www.drupal.org/u/neclimdul [13] https://www.drupal.org/u/greggles [14] https://www.drupal.org/u/larowlan [15] https://www.drupal.org/u/longwave [16] https://www.drupal.org/u/xjm [17] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org