SA-CONTRIB-2026-209: Critical severity drupal/menu_link_attributes vulnerability
This module enables you to add HTML attributes to menu links and their container elements (<li>). The module doesn't sufficiently sanitize the attributes it applies to menu link container elements. This vulnerability is mitigated by the fact that an attacker must have a role with the permissions "Administer menus and menu links" and "Use menu link attributes". In addition, an unsafe container attribute must already be configured by a user with the restricted permission "Administer menu link attributes". The default configuration is not affected.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/menu_link_attributesto a version that resolves this vulnerability.Fixed in 8.x-1.8