SA-CONTRIB-2026-203: Critical severity drupal/inline_formatter_field vulnerability
The Inline Formatter Field module allows site builders to template and style entities with a field. This module does not properly protect against template injection when parsing, allowing users to render protected data or execute unsafe Twig commands.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/inline_formatter_fieldto a version that resolves this vulnerability.Fixed in 4.2.0