SA-CONTRIB-2026-213: Critical severity drupal/freelinking vulnerability
This module enables you to configure a WIKI-like input filter that allows users to create links to site and external content. The module doesn’t sufficiently prevent page titles being viewed for certain privately-accessible URLs. This vulnerability is mitigated by the fact that an attacker must have access to use a text format with the Freelinking plugin configured to allow privately-accessible external URLs to be crawled. Site administrators may want to disable this functionality to evaluate any risk.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/freelinkingto a version that resolves this vulnerability.Fixed in 4.0.3 - Configuration
Disable the functionality that allows privately-accessible external URLs to be crawled when evaluating the risk.
Freelinking plugin Allow privately-accessible external URLs to be crawled = disabled
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites are exposed only where users can access a text format that uses the Freelinking plugin and is configured to crawl privately-accessible external URLs. The issue can reveal page titles for certain private URLs.
What access does an attacker need?
An attacker must be able to use the affected text format with the Freelinking plugin configured to allow crawling of privately-accessible external URLs.
What can be done while evaluating the risk?
Site administrators can disable the functionality that allows privately-accessible external URLs to be crawled.