—
DRUPAL-CONTRIB-2025-081
Details
The CKEditor5 Youtube module enhances content creation in Drupal by seamlessly integrating YouTube video embedding into the CKEditor 5 text editor.
The module doesn't sufficiently validate iframe sources under the scenario where a user embeds a video using the CKEditor YouTube integration leading to a Cross-site Scripting (XSS) vulnerabiity. This vulnerability is mitigated by the fact that an attacker must have a role with necessary permissions to use CKEditor Youtube embed button.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/ckeditor5_youtube
Introduced in:
0Fixed in: 1.0.4Upgrade drupal/ckeditor5_youtube to 1.0.4 or newer (ecosystem packagist:https://packages.drupal.org/8).