SA-CORE-2025-001: XSS
Drupal core doesn't sufficiently filter error messages under certain circumstances, leading to a reflected Cross Site Scripting vulnerability (XSS). Sites are encouraged to update. There are not yet public documented steps to exploit this, but there may be soon given the nature of this issue. This issue is being protected by Drupal Steward. Sites that use Drupal Steward are already protected, but are still encouraged to upgrade in the near future.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2025-001?
SA-CORE-2025-001 is categorized as a reflected Cross Site Scripting (XSS) vulnerability.
How do I fix SA-CORE-2025-001?
To fix SA-CORE-2025-001, update your Drupal site to a version above 11.1.
What versions of Drupal are affected by SA-CORE-2025-001?
SA-CORE-2025-001 affects Drupal versions 10.3, 10.4, 11.0, and 11.1.
What type of vulnerability is SA-CORE-2025-001?
SA-CORE-2025-001 is a Cross Site Scripting (XSS) vulnerability due to insufficient filtering of error messages.
Are there known exploits for SA-CORE-2025-001?
As of now, there are no public documented steps to exploit SA-CORE-2025-001, but it could change in the future.