—
DRUPAL-CONTRIB-2026-044
Details
The Examples for Developers project aims to provide high-quality, well-documented API examples for a broad range of Drupal core functionality.
The "Read from a file" feature implemented by the file\_example submodule can be used to expose any file that PHP can access. Therefore, the file\_example sub-module is being removed from Examples for Developers until a version demonstrating file security best practices can be added back in the future. Developers who based a new module on this example should review their code for an access bypass.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/examples
Introduced in:
0Fixed in: 4.0.6Upgrade drupal/examples to 4.0.6 or newer (ecosystem packagist:https://packages.drupal.org/8).