Drupal core
This is the main software that runs the website.
3 security fixes in one update. Drupal core fixed 3 separate security bugs this week: 2 cross site scripting, 1 gadget chain. One update covers all of them. The most serious, SA-CORE-2026-001, is explained here and the full list is at the end of the card.
A visitor without an account could cause unsafe code to run in message boxes on the site. This could allow them to see or change some information but they could not take over the whole site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youEvery Drupal site on an affected version.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Drupal core to 11.3.7, 11.2.11, 10.6.7 or 10.5.9, whichever branch you are on.
For developers: what the fix changed
The fix sanitises button attributes for AJAX modal dialog boxes by applying Xss::filter to string values in the render method of core/lib/Drupal/Core/Ajax/OpenDialogCommand.php.
Also in this release The release also fixes two other security advisories and updates Composer to version 2.9.7.
composer.lock+11 −11composer/Metapackage/CoreRecommended/composer.json+1 −1composer/Metapackage/PinnedDevDependencies/composer.json+2 −2core/lib/Drupal.php+1 −1core/lib/Drupal/Core/Ajax/OpenDialogCommand.php+15 −0 fixcore/lib/Drupal/Core/Template/Attribute.php+3 −0core/modules/ckeditor5/src/Controller/EntityLinkSuggestionsController.php+1 −1core/modules/views/src/ViewExecutable.php+27 −0
- Critical · Cross site scripting · SA-CORE-2026-001
- Moderately critical · Cross site scripting · SA-CORE-2026-003
- Moderately critical · Gadget Chain · SA-CORE-2026-002