SA-CONTRIB-2026-154: Critical severity drupal/webform vulnerability
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. The module provides JavaScript behaviours for announcing dynamic form updates to assistive technologies. In some configurations, due to improper sanitisation, specially crafted announcement text could create a cross-site scripting risk for users interacting with the affected Webform.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/webformto a version that resolves this vulnerability.Fixed in 6.2.12Fixed in 6.3.1
Event History
Frequently Asked Questions
Which deployments are potentially exposed?
The risk applies only to some Webform configurations. The available information does not identify the specific configuration conditions.
What is required for exploitation?
An attacker would need to introduce specially crafted announcement text, and a user would need to interact with the affected Webform. The issue is associated with JavaScript behaviours that announce dynamic form updates to assistive technologies.