drupal/layout_builder_perms is vulnerable to Missing Authorization
43
Medium Risk
Affected versions of this package are vulnerable to Access Bypass due to insufficient permission controls in the section-adding functionality. The module fails to properly restrict users with specific permissions, including View published content, Create/Edit content for relevant types, Configure layout overrides, and Access Layout Builder page, from adding unauthorized sections during content editing. An attacker possessing these permissions could exploit this flaw to manipulate page layouts beyond their intended privileges, potentially injecting malicious components or altering page structures.
You are affected if you are using a version that falls within the vulnerable range.
drupal/layout_builder_perms is vulnerable to Missing Authorization in versions 0.1.0 - 2.2.0.
Upgrade the drupal/layout_builder_perms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant