PT-2026-2967 · Packagist · Drupal/Ginvite

Published

2026-01-14

·

Updated

2026-01-14

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables allows group managers to invite people into their group.
The module doesn't sufficiently check access under certain circumstances, allowing unauthorized users to access the group's content.
This vulnerability is mitigated by the fact that it only occurs when certain uncommon actions are taken by a user with the permission to create group invites.

Related Identifiers

DRUPAL-CONTRIB-2026-001

Affected Products

Drupal/Ginvite