Intel

AIKIDO-2025-10815

drupal/core is vulnerable to Information Disclosure

Information DisclosureCVE-2025-13083 Published Nov 17, 2025

60

Medium Risk

This Affects:

PHPdrupal/core
8.0.0 - 10.4.8
Fixed in 10.4.9
10.5.0 - 10.5.5
Fixed in 10.5.6
11.0.0 - 11.1.8
Fixed in 11.1.9
11.2.0 - 11.2.7
Fixed in 11.2.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Information Disclosure: the Drupal core system module may incorrectly serve private or temporary files with the HTTP header Cache-Control: public, allowing them to be cached by intermediaries such as Varnish or CDNs. This can expose sensitive files to unauthorized users.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/core is vulnerable to Information Disclosure in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7.

How to fix this

Upgrade the drupal/core library to the patch version.