Add tests for SA-CORE-2025-004: Link field attribute XSS

Created on 14 June 2025, 10 days ago

Problem/Motivation

This is a public followup for SA-CORE-2025-004 . Link field attributes were not properly sanitized, which could lead to XSS. This issue will add the test coverage used in the private security issue.

Proposed resolution

Add tests from private issue: https://security.drupal.org/node/169733 (restricted access)

Remaining tasks

TBD

📌 Task
Status

Active

Version

11.0 🔥

Component

link.module

Created by

🇺🇸United States xjm

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024