Intel

AIKIDO-2026-869158

drupal/core is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-55805 Published 5 days ago

52

Medium Risk

This Affects:

PHPdrupal/core
0.0.1 - 10.6.12
Fixed in 10.6.13
11.0.0 - 11.3.13
Fixed in 11.3.14
11.4.0 - 11.4.3
Fixed in 11.4.4
Are you affected? Scan for Free

TL;DR

The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability. This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use the Layout Builder module.

Background info

drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 10.6.12, 11.0.0 - 11.3.13 and 11.4.0 - 11.4.3.

How to fix this

Upgrade the drupal/core library to the patch version.