GHSA-52jr-x6h6-xj6g
GitHub Security Advisory
Drupal core vulnerable to improper error handling
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
Affected Packages
Packagist
drupal/core
Affected versions:
10.0.0
(fixed in 10.2.10)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.