SA-CORE-2026-003: Critical severity Drupal Drupal vulnerability
Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross site scripting attack against another user.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.3
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2026-003?
The severity of SA-CORE-2026-003 is rated as critical due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix SA-CORE-2026-003?
To fix SA-CORE-2026-003, upgrade your Drupal installation to version 11.4 or later.
Who is affected by SA-CORE-2026-003?
SA-CORE-2026-003 affects users running Drupal version 11.3 who have CKEditor 5 linked entity suggestions.
What type of attack does SA-CORE-2026-003 enable?
SA-CORE-2026-003 enables stored cross-site scripting (XSS) attacks against other users.
Is there a workaround for SA-CORE-2026-003 if I cannot upgrade?
There are no effective workarounds for SA-CORE-2026-003; an upgrade is necessary to mitigate the vulnerability.