Junglewise Threat Intelligence

CVE-2026-16638: Drupal Media Folders stored cross-site scripting

CVE-2026-16638 · Severity: medium · CVSS 6.1 · Published 2026-08-25

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal Media Folders is a module that provides a file management interface for organizing media assets within Drupal sites. An attacker with permission to create or edit media items or folders can inject malicious scripts that execute when other administrators view the media browser, potentially allowing session hijacking or unauthorized actions. The vulnerability is limited to users with existing editing permissions and affects versions before 1.0.8.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the Media Folders module where media item and folder names and descriptions are not properly sanitized before display in the media browser interface. An authenticated attacker with permissions to create or edit media items or folders can inject malicious JavaScript payloads that persist in the database and execute in the browsers of other users—typically administrators—who view the media browser. The attack requires authentication and specific media management permissions, limiting the attack surface. The vulnerability has been fixed in version 1.0.8 and administrators should upgrade to this version or newer.

Affected products

  • Drupal Media Folders 0.0.0 to 1.0.7

Timeline

  • 2026-07-22: disclosed
  • 2026-07-21: patched: Version 1.0.8 released
  • 2026-08-25: advisory

References