Project:
Date:
2026-February-25
Vulnerability:
Cross-site scripting
Affected versions:
<3.1.3
CVE IDs:
CVE-2026-3217
Description:
This module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site.
The module doesn't sufficiently sanitize user input, leading to a reflected Cross-site scripting (XSS) vulnerability.
Solution:
Install the latest version:
- If you are using the "SAML SSO- Service Provider" module for Drupal, upgrade to SAML SSO- Service Provider 3.1.3.
Reported By:
- Drew Webber (mcdruid) of the Drupal Security Team
Fixed By:
Coordinated By:
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team