PT-2026-107760 · Packagist · Drupal/Menu Link Attributes
CVE-2026-107306
·
Published
2026-10-07
·
Updated
2026-10-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables you to add HTML attributes to menu links and their container elements (
<li>).The module doesn't sufficiently sanitize the attributes it applies to menu link container elements.
This vulnerability is mitigated by the fact that an attacker must have a role with the permissions "Administer menus and menu links" and "Use menu link attributes". In addition, an unsafe container attribute must already be configured by a user with the restricted permission "Administer menu link attributes". The default configuration is not affected.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal/Menu Link Attributes