CVE-2025-13081: Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
Other sources
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13081?
CVE-2025-13081 is considered a critical vulnerability due to its potential for object injection attacks in Drupal core.
How do I fix CVE-2025-13081?
To mitigate CVE-2025-13081, update your Drupal core to versions 10.5.6 or later, or to 11.1.9 or later.
Which versions of Drupal are affected by CVE-2025-13081?
CVE-2025-13081 affects Drupal core versions from 8.0.0 before 10.4.9, 10.5.0 before 10.5.6, and 11.0.0 before 11.1.9, among others.
What kind of attack does CVE-2025-13081 allow?
CVE-2025-13081 allows for improperly controlled modification of dynamically-determined object attributes, leading to object injection.
Is CVE-2025-13081 a known issue in Drupal?
Yes, CVE-2025-13081 is a recognized vulnerability and has been documented in Drupal's security advisory.