SA-CONTRIB-2026-123: Critical severity drupal/component_blocks vulnerability
This module enables you use UI Patterns with blocks, for use in Layout Builder. The module doesn't sufficiently validate user input before passing to token replacement. This vulnerability is mitigated by the fact that an attacker must have a role with the ability to edit layout builder layouts.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/component_blocksto a version that resolves this vulnerability.Fixed in 1.2.7
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Sites using the drupal/component_blocks module with Layout Builder are exposed when users have a role that can edit Layout Builder layouts. The advisory identifies that permission as a mitigating factor.
What access does an attacker need to exploit it?
An attacker must be able to edit Layout Builder layouts through an assigned role. The issue involves insufficient validation of user input before it is passed to token replacement.