Paragraphs
2 security fixes in one update. Paragraphs fixed 2 separate security bugs this week: 2 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-061, is explained here and the full list is at the end of the card.
Anyone without logging in could bypass access checks to reach child sections of library items through data feeds. They could alter or create new library sections on the website. They could not view any restricted information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the library feature is in use and general write access to these sections is allowed through another module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Paragraphs to 8.x-1.21.
For developers: what the fix changed
The fix updates `ParagraphAccessControlHandler::checkAccess()` to properly enforce access checks on child paragraphs of library items, and modifies `LibraryItemAccessControlHandler::checkAccess()` to forward view access checks to the referenced paragraph. It also adds `paragraphs_library_query_paragraphs_library_item_access_alter()` in `paragraphs_library.module` to restrict query access to unpublished library items.
Also in this release The release also updates the inline_entity_form dependency and improves mobile behaviour for sticky content tabs.
composer.json+1 −1css/paragraphs.widget.css+13 −13css/paragraphs.widget.scss+20 −17modules/paragraphs_library/paragraphs_library.module+42 −0 fixmodules/paragraphs_library/src/LibraryItemAccessControlHandler.php+13 −7 fixsrc/ParagraphAccessControlHandler.php+9 −3 fix
- Moderately critical · Access bypass · SA-CONTRIB-2026-061
- Less critical · Access bypass · SA-CONTRIB-2026-060