—
DRUPAL-CONTRIB-2026-178
Details
The Project Browser module enables you to apply recipes and enable modules from the web user interface.
The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/project_browser
Introduced in:
0Fixed in: 2.0.3Upgrade drupal/project_browser to 2.0.3 or newer (ecosystem packagist:https://packages.drupal.org/8).