Project: 
Date: 
2026-February-25
Vulnerability: 
Arbitrary file upload, Cross-site scripting
Affected versions: 
<2.17.5
CVE IDs: 
CVE-2026-3215
Description: 

This module integrates with Islandora, an open-source digital asset management (DAM) framework. Islandora integrates with various open-source services, which can be run in a distributed environment.

The module doesn't sufficiently sanitize URI paths for its custom route used for attaching media to nodes, which can also lead to cross-site scripting and other vulnerabilities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "create media" and the ability to edit the node the media is being attached to.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: