Executive brief
The Cloud module for Drupal, which allows administrators to manage cloud resources, fails to properly sanitize Git repository URLs and branch names before passing them to system commands. This enables an authenticated attacker with permissions to edit cloud server templates to execute arbitrary operating system commands with the privileges of the web server user, potentially leading to full system compromise.
Technical details
The vulnerability is a command injection flaw in the Kubernetes submodule where unsanitized user input from Git branch and repository URL fields is directly passed to shell commands. An attacker with "add or edit cloud server templates" permission (and optionally "launch cloud server template" permission depending on the exploitation path) can inject shell metacharacters to execute arbitrary commands as the web server user. The vulnerability affects all versions before 7.0.1.
Affected products
- Drupal Cloud <7.0.1
Timeline
- 2026-09-23: disclosed: Security advisory SA-CONTRIB-2026-177 published