PT-2025-47345 · Drupal · Drupal

Anna Kalata

+10

·

Published

2025-11-18

·

Updated

2025-11-25

·

CVE-2025-13081

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions 8.0.0 through 10.4.9 Drupal versions 10.5.0 through 10.5.6 Drupal versions 11.0.0 through 11.1.9 Drupal versions 11.2.0 through 11.2.7
Description Drupal core contains an improperly controlled modification of dynamically-determined object attributes, leading to Object Injection. This allows for potential manipulation of objects within the system.
Recommendations Update Drupal core to version 10.4.9 or later. Update Drupal core to version 10.5.6 or later. Update Drupal core to version 11.1.9 or later. Update Drupal core to version 11.2.8 or later.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2025-13081
CVE-2025-13081
DRUPAL-CORE-2025-006
GHSA-M6VV-VCJ8-W8M7

Affected Products

Drupal