Project:
Project machine name:
tawk_toDate:
2026-September-23
Vulnerability:
Cross Site Request Forgery
Affected versions:
<3.0.4
CVE IDs:
CVE-2026-96388
Description:
This module provides integration of the tawk.to live chat for Drupal sites.
The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.
Solution:
Reported By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team