—
DRUPAL-CONTRIB-2025-034
Details
The baguetteBox.js module provides integration with baguetteBox.js library.
The module doesn't sufficiently sanitize user-supplied text values leading to a cross site scripting vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/baguettebox
Introduced in:
0Fixed in: 2.0.4Upgrade drupal/baguettebox to 2.0.4 or newer (ecosystem packagist:https://packages.drupal.org/8).