SA-CONTRIB-2026-217: CSRF
Advanced File System turns Drupal's file storage into a manageable, observable and maintainable subsystem. The Advanced Filesystem: Backup submodule does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability. The vulnerability is mitigated by the fact that advancedfilesystembackup module must be enabled.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/advanced_filesystemto a version that resolves this vulnerability.Fixed in 1.0.28