PT-2026-97666 · Packagist · Drupal/Project Browser

CVE-2026-96374

·

Published

2026-09-23

·

Updated

2026-09-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Project Browser module enables you to apply recipes and enable modules from the web user interface.
The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-96374
DRUPAL-CONTRIB-2026-178

Affected Products

Drupal/Project Browser