drupal/plotly_js is vulnerable to Deserialization of Untrusted Data
81
High Risk
The Plotly.js Graphing module stores graph data as PHP-serialized strings, and in certain conditions an attacker can write crafted serialized data directly to that field, leading to a PHP Object Injection vulnerability when it's unserialized. Exploitation requires the attacker to have edit permissions on a content entity with a plotly_js_graph field, plus either JSON:API enabled with the non-default "accept all CRUD operations" setting, or some other means of writing directly to the field — which meaningfully limits real-world exploitability.
You are affected if you are using a version that falls within the vulnerable range.
drupal/plotly_js is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 3.0.1.
Upgrade the drupal/plotly_js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant