DRUPAL-CONTRIB-2026-180

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/mermaid_diagram_field/DRUPAL-CONTRIB-2026-180.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-180
Aliases
  • CVE-2026-96384
Published
2026-09-23T17:07:17Z
Modified
2026-09-23T19:15:05Z
Summary
[none]
Details

This module enables you to add mermaid diagram that displays either inline on an entity or optionally in a modal.

The module doesn't sufficiently respect default revision behavior and does not properly limit access to the modal content.

This vulnerability is mitigated by the fact that an attacker must have the modal display option enabled for the field, or otherwise know the route of the modal and entity ID.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/mermaid_diagram_field

Package

Name
drupal/mermaid_diagram_field
Purl
pkg:composer/drupal/mermaid_diagram_field?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.4
Fixed
1.0.9
Database specific
Show details
{
    "constraint":  ">=1.0.4 <1.0.9"
}

Database specific

affected_versions
">=1.0.4 <1.0.9"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/mermaid_diagram_field/DRUPAL-CONTRIB-2026-180.json"