Executive brief
The Anti-Spam by CleanTalk module for Drupal, which protects websites from automated spam and bot registrations, contains a security flaw. An attacker who can intercept or manipulate the communication between the website and the CleanTalk cloud service could inject malicious scripts into the site's administrative interface. This could lead to unauthorized actions being performed in the context of a site administrator's session.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Anti-Spam by CleanTalk module for Drupal. The vulnerability is located within the _cleantalk_die() and ct_die() functions, which fail to properly sanitize messages received from the CleanTalk cloud API before rendering them in HTML output. An attacker could exploit this by influencing the API response, for example via a man-in-the-middle (MitM) attack or by compromising the upstream API server, to execute arbitrary JavaScript in the victim's browser. The issue is fixed in version 9.7.1.
Affected products
- Drupal Anti-Spam by CleanTalk 0.0.0 to 9.7.0
Timeline
- 2026-06-03: advisory: Drupal security advisory SA-CONTRIB-2026-042 published
- 2026-06-16: patched: Version 9.7.2 released (9.7.1 contained the fix)
- 2026-07-10: disclosed: CVE-2026-10770 published to NVD