The Project Browser module enables you to apply recipes and enable modules from the web user interface.
The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF).
{ "constraint": "<2.0.3" }
{ "constraint": ">=2.1.0 <2.1.5" }
"<2.0.3 || >=2.1.0 <2.1.5"
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/project_browser/DRUPAL-CONTRIB-2026-178.json"