Executive brief
The Tawk.to live chat integration module for Drupal sites fails to validate certain requests, allowing attackers to exploit a cross-site request forgery (CSRF) vulnerability. An attacker can trick an authenticated Drupal user into performing unintended actions, such as modifying site settings or account configurations, without the user's knowledge or consent.
Technical details
The module does not sufficiently validate CSRF tokens on certain requests, allowing unauthenticated attackers to forge requests on behalf of authenticated users. The vulnerability requires user interaction (tricking an authenticated admin or user into visiting a malicious page) but no additional privileges. Exploitation allows an attacker to perform administrative actions within the module context. The vulnerability is fixed in version 3.0.4.
Affected products
- Drupal Tawk.to <3.0.4
Timeline
- 2026-09-23: disclosed: DRUPAL-CONTRIB-2026-184 published