Executive brief
The Drupal Formatter Field module, which allows website administrators to customize how specific content fields are displayed, contains a critical security flaw. An attacker with permission to edit content could inject malicious data that, when processed by the server, allows them to execute unauthorized code or take full control of the website. This risk is significantly higher if the site has certain non-default data-sharing features (JSON:API) enabled.
Technical details
The Formatter Field module for Drupal is vulnerable to PHP Object Injection (CWE-915/CWE-502) because it stores data as PHP-serialized strings and fails to properly validate this data before unserialization. An attacker with the ability to edit content entities containing a formatter_field can inject malicious serialized objects. This is particularly exploitable if the JSON:API module is enabled with write operations permitted, allowing direct modification of field values. Successful exploitation can lead to arbitrary code execution depending on the available 'POP chains' in the environment. The issue is resolved in version 2.0.0.
Affected products
- Drupal Formatter Field 0.0.0 to 1.9.9
Timeline
- 2026-06-16: patched: Version 2.0.0 released
- 2026-06-17: advisory: Drupal security advisory SA-CONTRIB-2026-048 published
- 2026-07-10: disclosed: CVE-2026-12535 published to NVD