DEV Community

yutianle
yutianle

Posted on

Detecting unexpected custom attributes after CVE-2026-96367

Detecting unexpected custom attributes after CVE-2026-96367

Vulnerability overview

SA-CONTRIB-2026-162 documents CVE-2026-96367, a cross-site scripting flaw in the Drupal contributed Webform module. Drupal published the advisory on 2026-September-23 and rated it Moderately critical at 13/25.

Mechanism and exploitation conditions

According to the advisory, the module does not sufficiently restrict access to the custom attributes YAML editor. A user holding permission to create or edit webforms, but not permission to edit webform source, may add custom attributes, which the module renders and which therefore lead to cross-site scripting.

Impact

The affected artifact is a stored configuration, not a one-time request, so injected content stays attached to the form. Detection therefore looks at form configuration and at the roles able to change it. The advisory names the attacker's role requirement as the limiting factor, and its vector is AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Uncommon.

Affected products and scope

On 6.2.x, Webform releases below 6.2.12 are affected. On 6.3.x, releases from 6.3.0 up to but not including 6.3.1 are affected.

Exposure context

A ZoomEye search for app="Drupal" returned 436,325 instances. The number reflects the Drupal product fingerprint and cannot be read as a count of vulnerable Webform installations.

Remediation and mitigations

Install Webform 6.2.12 on the 6.2.x branch or Webform 6.3.1 on the 6.3.x branch. After patching, review form definitions for custom attributes that no administrator recognises and confirm that the create or edit webform permission is limited to roles that genuinely need it.

References

Top comments (0)