—
DRUPAL-CONTRIB-2025-122
Details
This module enables integration between Next.js and Drupal for headless CMS functionality.
When installed, the module automatically enables cross-origin resource sharing (CORS) with insecure default settings (`Access-Control-Allow-Origin: *`), overriding any `services.yml` CORS configuration. This allows any origin to make cross-origin requests to the site without administrator knowledge or consent.
This vulnerability affects all installations as there are no configuration options to disable this behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/next
Introduced in:
0Fixed in: 1.6.4Upgrade drupal/next to 1.6.4 or newer (ecosystem packagist:https://packages.drupal.org/8).