DRUPAL-CONTRIB-2026-184

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/tawk_to/DRUPAL-CONTRIB-2026-184.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-184
Aliases
  • CVE-2026-96388
Published
2026-09-23T17:14:48Z
Modified
2026-09-23T19:15:04Z
Summary
[none]
Details

This module provides integration of the tawk.to live chat for Drupal sites.

The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/tawk_to

Package

Name
drupal/tawk_to
Purl
pkg:composer/drupal/tawk_to?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.4
Database specific
Show details
{
    "constraint":  "<3.0.4"
}

Database specific

affected_versions
"<3.0.4"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/tawk_to/DRUPAL-CONTRIB-2026-184.json"