Date: 
2026-September-02
Vulnerability: 
Cross site scripting
Affected versions: 
<1.2.7
CVE IDs: 
CVE-2026-84915
Description: 

This module enables you use UI Patterns with blocks, for use in Layout Builder.

The module doesn't sufficiently validate user input before passing to token replacement.

This vulnerability is mitigated by the fact that an attacker must have a role with the ability to edit layout builder layouts.

Solution: 

Install the latest version:

Fixed By: 
Coordinated By: