SA-CONTRIB-2026-117: XSS

Published Aug 26, 2026
·
Updated

Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons. Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability. Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.

Credit

Drew Webber (mcdruid)(the Drupal Security Team)

Affected Software

1 affected component
drupal/slick

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.x-2.1
  2. Configuration

    Ensure Slick UI option sets used for carousel buttons do not include unvalidated user input/HTML to prevent XSS (module previously did not sufficiently validate user input).

    Slick (Slick UI sub-module) Carousel button HTML input validation = disable/avoid allowing unvalidated HTML in Slick option sets for carousel buttons

Event History

Aug 26, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Drupal sites using the Slick UI sub-module are exposed if they use Slick option sets that can contain HTML for carousel buttons and are running a release without the input-validation fix.

2

What would an attacker need to exploit it?

An attacker would need a way to supply malicious HTML through Slick option-set input that is used for carousel buttons. The provided information does not identify the specific permissions or input path required.

3

Is there a known fixed release?

Yes. The issue was fixed in Slick version 8.x-2.1, although that release was not initially marked as a security release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203