Intel

AIKIDO-2025-10560

drupal/layout_builder_perms is vulnerable to Missing Authorization

Missing AuthorizationCVE-2025-8996 Published Aug 18, 2025

43

Medium Risk

This Affects:

PHPdrupal/layout_builder_perms
0.1.0 - 2.2.0
Fixed in 2.2.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Access Bypass due to insufficient permission controls in the section-adding functionality. The module fails to properly restrict users with specific permissions, including View published content, Create/Edit content for relevant types, Configure layout overrides, and Access Layout Builder page, from adding unauthorized sections during content editing. An attacker possessing these permissions could exploit this flaw to manipulate page layouts beyond their intended privileges, potentially injecting malicious components or altering page structures.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/layout_builder_perms is vulnerable to Missing Authorization in versions 0.1.0 - 2.2.0.

How to fix this

Upgrade the drupal/layout_builder_perms library to the patch version.