Junglewise Threat Intelligence

CVE-2026-8493: Drupal Colorbox Inline cross-site scripting in data-colorbox-inline attribute

CVE-2026-8493 · Severity: info · CVSS 0 · Published 2026-05-19

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Colorbox Inline module for Drupal, which allows website content to be displayed in stylized overlay windows, contains a security flaw. An attacker with permissions to edit website content could inject malicious scripts that execute in the browsers of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Drupal Colorbox Inline module versions prior to 2.1.1. The root cause is the failure to sufficiently sanitize the 'data-colorbox-inline' attribute value before it is processed by jQuery. An attacker with a role permitted to enter HTML tags containing specific data attributes can exploit this to execute arbitrary JavaScript in the context of a victim's browser. The vulnerability is mitigated by the requirement for specific administrative or content-creation permissions. Users should upgrade to version 2.1.1 to resolve the issue.

Affected products

  • Drupal Colorbox Inline >= 0.0.0, < 2.1.1

Timeline

  • 2026-05-13: advisory: Drupal security advisory SA-CONTRIB-2026-036 published
  • 2026-05-19: disclosed: CVE-2026-8493 published to NVD
  • 2026-05-13: patched: Version 2.1.1 released to address the vulnerability

References