Project:
Project machine name:
inline_formatter_fieldDate:
2026-October-07
Vulnerability:
Server-side template injection
Affected versions:
<4.2.0
CVE IDs:
CVE-2026-107264
Description:
The Inline Formatter Field module allows site builders to template and style entities with a field.
This module does not properly protect against template injection when parsing, allowing users to render protected data or execute unsafe Twig commands.
Solution:
Install the latest version:
- If you use the Inline Formatter Field module, upgrade to Inline Formatter Field 4.2.0
Reported By:
Fixed By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team