Vulnerability DRUPAL-CONTRIB-2026-209

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 hours ago
October 07, 2026 at 04:34 PM UTC
No summary available

Details

This module enables you to add HTML attributes to menu links and their container elements (<li>).

The module doesn't sufficiently sanitize the attributes it applies to menu link container elements.

This vulnerability is mitigated by the fact that an attacker must have a role with the permissions "Administer menus and menu links" and "Use menu link attributes". In addition, an unsafe container attribute must already be configured by a user with the restricted permission "Administer menu link attributes". The default configuration is not affected.

Timeline

Published
11 hours ago
October 07, 2026 at 04:34 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 08:15 PM UTC