Executive brief
Drupal Commerce Core, a framework used to build e-commerce websites, contains a security vulnerability that could allow attackers to inject malicious scripts into order receipt emails. This occurs when the platform fails to properly clean customer comments before including them in automated email templates. If exploited, this could lead to unauthorized actions or data theft when a store administrator or customer views the affected email.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Drupal Commerce Core due to insufficient sanitization of customer-provided input. Specifically, the 'customer_comments' checkout pane fails to neutralize input before it is rendered in the order receipt email template. An unauthenticated attacker can submit malicious scripts within the comments field during checkout. The vulnerability is triggered when the resulting email is viewed in a web-based email client or within the Drupal administrative interface. This issue affects installations where the 'commerce_checkout' module is enabled and the optional 'Comments' pane is active. The vulnerability is fixed in version 3.3.6.
Affected products
- Drupal Commerce Core 3.3.0 to 3.3.5
Timeline
- 2026-06-02: patched: Version 3.3.6 released to address the vulnerability.
- 2026-06-03: advisory: Drupal security advisory SA-CONTRIB-2026-041 published.
- 2026-07-10: disclosed: CVE-2026-10769 published to the NVD.