DRUPAL-CONTRIB-2026-129

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/media_library_importer/DRUPAL-CONTRIB-2026-129.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-129
Aliases
  • CVE-2026-81163
Published
2026-09-02T16:35:30Z
Modified
2026-09-02T19:55:49Z
Summary
[none]
Details

A module to import media files into media library.

The import folder is a plain textfield with no validation. Point it at any directory the web user can read, and the importer copies every file whose extension matches a selected media type into the public files directory and publishes it as a Media entity. Files that were deliberately kept outside the webroot, such as a private file store, become downloadable by anonymous visitors at a predictable URL.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/media_library_importer

Package

Name
drupal/media_library_importer
Purl
pkg:composer/drupal/media_library_importer?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.6
Database specific
Show details
{
    "constraint": "<2.1.6"
}

Database specific

affected_versions
"<2.1.6"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/media_library_importer/DRUPAL-CONTRIB-2026-129.json"