Project:
Date:
2025-April-16
Vulnerability:
Cross Site Scripting
Affected versions:
<2.0.4 || >=3.0.0 <3.0.1
CVE IDs:
CVE-2025-3733
Description:
The baguetteBox.js module provides integration with baguetteBox.js library.
The module doesn't sufficiently sanitize user-supplied text values leading to a cross site scripting vulnerability.
Solution:
Install the latest version:
- If you use the baguetteBox.js module 3.0.x, upgrade to baguetteBox.js 3.0.1
- If you use the baguetteBox.js module 2.0.x, upgrade to baguetteBox.js 2.0.4
Reported By:
- Pierre Rudloff (prudloff) Provisional Member of the Drupal Security Team
Fixed By:
- Pierre Rudloff (prudloff) Provisional Member of the Drupal Security Team
- Stephen Mustgrave (smustgrave)
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team