SA-CONTRIB-2026-175: Critical severity drupal/webform vulnerability

Published Sep 23, 2026
·
Updated

The Webform module allows site builders to create forms, collect submissions, and render submitted values in configurable formats. Webform does not sufficiently exclude certain format templates from token replacement. This can allow an attacker to submit data that is evaluated as template code when a submission is rendered. Depending on the site configuration and enabled modules, this may lead to information disclosure, stored cross-site scripting, or remote code execution. This vulnerability is mitigated by the fact that an affected webform must be configured with a custom multiple-value item format that includes submission-value tokens. Some impacts may also depend on additional enabled modules or site-specific configuration.

Credit

Michael Maturi (michaelmaturi)

Affected Software

1 affected componentFixes available
drupal/webform<6.2.12, <6.3.1
6.2.126.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade drupal/webform to a version that resolves this vulnerability.

    Fixed in 6.2.12Fixed in 6.3.1

Event History

Sep 23, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

Which Webform configurations are exposed?

An affected webform must use a custom multiple-value item format that includes submission-value tokens. Impact also depends on the site's configuration and, for some outcomes, additional enabled modules.

2

What does an attacker need to exploit this issue?

The attacker needs to be able to submit data to a webform whose configured rendering format includes submission-value tokens. Their submitted value can then be evaluated as template code when the submission is rendered.

3

How can administrators identify potentially affected forms?

Review webforms for custom multiple-value item formats and determine whether those formats include submission-value tokens. Forms without that required configuration are not described as affected by this issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203