SA-CONTRIB-2026-204: Critical severity drupal/leaflet vulnerability
Published Oct 7, 2026
·Updated
The Leaflet module provides integration with the Leaflet JS mapping library. Under certain circumstances, when the Leaflet field formatter builds a map it does not filter content titles, leading to a stored cross-site scripting vulnerability. This vulnerability is mitigated by the fact an attacker needs to have permission to create or edit content that is used in a Leaflet map.
Credit
Marcus Johansson (marcus_johansson)
Affected Software
1 affected componentFixes available
drupal/leaflet<10.4.13
10.4.13
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/leafletto a version that resolves this vulnerability.Fixed in 10.4.13
Event History
Oct 7, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which users could exploit this issue?
An attacker needs permission to create or edit content that is used in a Leaflet map. Users without those content permissions are mitigated from exploiting the issue.