GHSA-v8wr-r69p-mmwx
GitHub Security Advisory
Unrestricted Upload of File with Dangerous Type in Drupal core
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.
Affected Packages
Packagist
drupal/core
Affected versions:
8.0.0
(fixed in 8.9.19)
Packagist
drupal/core
Affected versions:
9.1.0
(fixed in 9.1.13)
Packagist
drupal/core
Affected versions:
9.2.0
(fixed in 9.2.6)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.