Junglewise Threat Intelligence

CVE-2026-58591: Drupal Colorbox cross-site scripting in content overlays

CVE-2026-58591 · Severity: info · CVSS 4.8 · Published 2026-07-10

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Drupal Colorbox module, which allows websites to display images and content in a pop-up overlay, contains a security flaw that could allow malicious code to be injected into pages. If exploited, an attacker could execute scripts in the browser of other users, potentially leading to unauthorized actions or data theft. This risk is limited to scenarios where an attacker already has permission to post HTML content on the site.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Drupal Colorbox module due to improper neutralization of input during web page generation. The module fails to sufficiently sanitize content before displaying it within the Colorbox JavaScript library overlay. An attacker with a user role permitted to enter HTML content can exploit this to execute arbitrary JavaScript in the context of a victim's browser session. The vulnerability is mitigated by the requirement for specific user permissions (authenticated access with HTML entry rights) and complex attack conditions. The issue is addressed in versions 2.1.5 and 2.2.1.

Affected products

  • Drupal Colorbox < 2.1.5, 2.2.0

Timeline

  • 2026-07-01: advisory: Drupal Security Advisory SA-CONTRIB-2026-069 published
  • 2026-07-01: patched: Versions 2.1.5 and 2.2.1 released to fix the issue
  • 2026-07-10: disclosed: CVE-2026-58591 published to NVD

References

Related threats