CVE-2025-13081

CVE-2025-13081: Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006

Vendor Drupal
Product Drupal core
Weakness CWE-915
Published November 18, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

Key dates

Disclosure timeline

November 18, 2025 CVE published
February 26, 2026 Record updated