Drupal core
This is the underlying software that runs the entire website.
3 security fixes in one update. Drupal core fixed 3 separate security bugs this week: 2 cross site scripting, 1 information disclosure. One update covers all of them. The most serious, SA-CORE-2026-012, is explained here and the full list is at the end of the card.
A person with an ordinary account could put hidden code into the name of a layout block. If another person uses the layout editing screen, that code would run. This could let the first person see private information or change content on the site.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies to sites where people use the layout editing screen.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Drupal core to 11.4.4, 11.3.14 or 10.6.13, whichever branch you are on.
For developers: what the fix changed
The fix updates `core/modules/layout_builder/js/layout-builder.js` to use `textContent` instead of `innerHTML` when rendering the content preview placeholder label, preventing cross-site scripting.
Also in this release The release also includes fixes for two other vulnerabilities affecting the XSS utility and image style downloads, alongside version bumps.
composer.lock+5 −5composer/Metapackage/CoreRecommended/composer.json+2 −2composer/Metapackage/DevDependencies/composer.json+1 −1composer/Metapackage/PinnedDevDependencies/composer.json+2 −2core/lib/Drupal.php+1 −1core/lib/Drupal/Component/Utility/Xss.php+2 −0core/modules/image/src/Controller/ImageStyleDownloadController.php+9 −9core/modules/layout_builder/js/layout-builder.js+2 −2 fix
- Moderately critical · Cross site scripting · SA-CORE-2026-012
- Moderately critical · Cross site scripting · SA-CORE-2026-011
- Moderately critical · Information disclosure · SA-CORE-2026-010