Executive brief
The Drupal Development Environment module is a developer tool that suppresses email sending and logging in non-production environments. The module has an unpatched security vulnerability that has been abandoned by its maintainer, leaving the project unsupported and posing a risk to sites that use it. Drupal recommends uninstalling the module or finding an alternative solution.
Technical details
This advisory marks the Drupal Development Environment contributed module as unsupported due to an unpatched security vulnerability (CVE-2026-15088). The specific technical details of the vulnerability are not disclosed in the available advisory text, but the module is used to intercept and log email functionality in development environments to prevent accidental production email sends. The maintainer has abandoned the project and has not resolved the security issue. No patch is available, and the Drupal Security Team recommends either uninstalling the module or taking over maintainership through the community process. The CVSS score of 5.7 indicates a moderate-to-high severity issue, though the exact attack preconditions and impact remain undisclosed.
Affected products
- Drupal Development Environment all versions
Timeline
- 2026-07-22: disclosed
- 2026-08-25: advisory: Published to NVD