View online: https://www.drupal.org/sa-contrib-2025-041
Project: Colorbox [1] Date: 2025-April-23 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross Site Scripting
Affected versions: <2.1.3 CVE IDs: CVE-2025-3900 Description: Colorbox is a module that allows Images, and iframed or inline content to be displayed in a modal above the current page.
The Colorbox module doesn't sufficiently sanitize data attributes before opening modals.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.
Solution: Install the latest version:
* If you use the Colorbox module 2.1.x for Drupal 10 or above, upgrade to Colorbox 2.1.3 [3] * If you use the Colorbox module 2.0.x, upgrade to Colorbox 2.1.3 [4], as the 2.0.x branch becomes unsupported.
Reported By: * Pierre Rudloff (prudloff) [5]
Fixed By: * Jen Lampton (jenlampton) [6] * Paul McKibben (paulmckibben) [7]
Coordinated By: * Greg Knaddison (greggles) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team
[1] https://www.drupal.org/project/colorbox [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/colorbox/releases/2.1.3 [4] https://www.drupal.org/project/colorbox/releases/2.1.3 [5] https://www.drupal.org/u/prudloff [6] https://www.drupal.org/u/jenlampton [7] https://www.drupal.org/u/paulmckibben [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/poker10