SA-CONTRIB-2026-137: XSS
Published Sep 9, 2026
·Updated
The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed. The module does not sufficiently validate or sanitize the RSS feed it generates, resulting in a stored cross-site scripting (XSS) vulnerability.
Credit
Marcus Johansson (marcus_johansson)
Affected Software
1 affected componentFixes available
drupal/feed_block<3.0.2, <2.0.2
3.0.22.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/feed_blockto a version that resolves this vulnerability.Fixed in 3.0.2Fixed in 2.0.2
Event History
Sep 9, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software