Junglewise Threat Intelligence

CVE-2025-31128: DRUPAL-CONTRIB-2025-032 - Gif Player Field creates a simple file field types that allows you to upload the GIF files and configure the output for this using the Field

CVE-2025-31128 · Severity: medium · CVSS 4 · Published 2025-04-09

Vendors: npm, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

gifplayer is a jQuery plugin that displays animated GIF images on web pages. A cross-site scripting (XSS) vulnerability in versions below 0.3.7 allows attackers to inject malicious scripts that execute in users' browsers, potentially leading to session hijacking, credential theft, or malware distribution.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw in gifplayer that permits arbitrary script injection. All versions prior to 0.3.7 are affected. The attack requires no authentication and is network-accessible, with no user interaction required beyond visiting a page that uses the vulnerable library. An attacker can inject JavaScript code that runs in the victim's browser context, potentially compromising user sessions and data. The vulnerability has been patched in version 0.3.7.

Affected products

  • Ruben Taelman gifplayer <0.3.7

Timeline

  • 2025-03-31: disclosed: Security advisory published
  • 2025-03-31: patched: Version 0.3.7 released with fix

References