{ "canonical_id": "drupal--a141e2f71d", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004", "summary": "
Drupal core Link field attributes are not sufficiently sanitized, which can lead to a Cross Site Scripting vulnerability (XSS).
\nThis vulnerability is mitigated by that fact that an attacker would need to have the ability to add specific attributes to a Link field, which typically requires edit access via core web services, or a contrib or custom module.
\nSites with the Link module disabled or that do not use any link fields are not affected.
Install the latest version:
\nAll versions of Drupal prior to 10.3 are end-of-life and do not receive security coverage from the Drupal Security Team.