SA-CORE-2026-001: XSS
Published Apr 15, 2026
·Updated
Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a cross-site scripting (XSS) vulnerability.
Credit
Murat Kekiç (murat_kekic)
Affected Software
1 affected componentFixes available
Drupal Drupal<10.5.9, <10.6.7, <11.2.11, <11.3.7
10.5.910.6.711.2.1111.3.7
Event History
Apr 15, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of SA-CORE-2026-001?
SA-CORE-2026-001 is considered a critical vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix SA-CORE-2026-001?
To fix SA-CORE-2026-001, upgrade your Drupal installation to versions 10.5.9, 10.6.7, 11.2.11, or 11.3.7.
3
Who is affected by SA-CORE-2026-001?
SA-CORE-2026-001 affects users running Drupal versions earlier than 10.5.9, 10.6.7, 11.2.11, or 11.3.7.
4
What types of attacks can be performed due to SA-CORE-2026-001?
SA-CORE-2026-001 can lead to cross-site scripting (XSS) attacks allowing attackers to execute malicious scripts in the browser of users.
5
Is there a workaround for SA-CORE-2026-001?
There are no known workarounds for SA-CORE-2026-001; updating to a patched version is the only effective solution.