SA-CONTRIB-2026-184: CSRF
Published Sep 23, 2026
·Updated
This module provides integration of the tawk.to live chat for Drupal sites. The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.
Credit
Tin Nguyen Huu (s4m0y3d)
Affected Software
1 affected componentFixes available
drupal/tawk_to<3.0.4
3.0.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/tawk_toto a version that resolves this vulnerability.Fixed in 3.0.4
Event History
Sep 23, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Drupal sites using the tawk.to live chat integration module are affected. Exploitation targets authenticated users of those sites.
2
What does an attacker need to exploit it?
An attacker needs to trick an authenticated user into making a request that performs an unintended action. The issue is caused by insufficient validation of certain requests.