Project:
Date:
2026-September-09
Vulnerability:
Cross-site scripting
Affected versions:
<2.0.2 || >=3.0.0 <3.0.2
CVE IDs:
CVE-2026-87939
Description:
The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed.
The module does not sufficiently validate or sanitize the RSS feed it generates, resulting in a stored cross-site scripting (XSS) vulnerability.
Solution:
Install the latest version:
- If you use the 3.x branch, upgrade to Feed Block 3.0.2.
- If you use the 2.x branch, upgrade to Feed Block 2.0.2.
Reported By:
Fixed By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Mark Fullmer (mark_fullmer)
- mmarler
Coordinated By:
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team