Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
Update drupal/core to 10.5.9; drupal/core to 10.6.7; drupal/core to 11.2.11; drupal/core to 11.3.7 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDrupal core is Vulnerable to Cross-Site Scripting affects drupal/core (composer), drupal/core (composer), drupal/core (composer), drupal/core (composer). Severity is medium. Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
AI coding agents often install or upgrade packages automatically in composer. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| drupal/corecomposer | >=8.0.0,<10.5.9 | 10.5.9 |
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
Update drupal/core to 10.5.9; drupal/core to 10.6.7; drupal/core to 11.2.11; drupal/core to 11.3.7 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDrupal core is Vulnerable to Cross-Site Scripting affects drupal/core (composer), drupal/core (composer), drupal/core (composer), drupal/core (composer). Severity is medium. Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
AI coding agents often install or upgrade packages automatically in composer. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| drupal/corecomposer | >=8.0.0,<10.5.9 | 10.5.9 |
| drupal/corecomposer | >=10.6.0,<10.6.7 | 10.6.7 |
|---|
| drupal/corecomposer | >=11.0.0,<11.2.11 | 11.2.11 |
|---|
| drupal/corecomposer | >=11.3.0,<11.3.7 | 11.3.7 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| drupal/corecomposer | >=10.6.0,<10.6.7 | 10.6.7 |
|---|
| drupal/corecomposer | >=11.0.0,<11.2.11 | 11.2.11 |
|---|
| drupal/corecomposer | >=11.3.0,<11.3.7 | 11.3.7 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard