Intel

AIKIDO-2026-10474

drupal/autologout is vulnerable to Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF)CVE-2026-4393 Published Apr 10, 2026

50

Medium Risk

This Affects:

PHPdrupal/autologout
0.0.1 - 1.6.0
Fixed in 1.7.0
2.0.0 - 2.0.1
Fixed in 2.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of this module doesn't sufficiently protect its routes from cross-site request forgery (CSRF), allowing the logout route to be triggered without user interaction.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/autologout is vulnerable to Cross-Site Request Forgery (CSRF) in versions 2.0.0 - 2.0.1 and 0.0.1 - 1.6.0.

How to fix this

Upgrade the drupal/autologout library to the patch version.