{"id":"DRUPAL-CONTRIB-2025-097","details":"The Layout Builder Advanced Permissions module enables you to have fine grained control over who can do what in editing pages built with Layout Builder.\n\nThe module doesn't sufficiently control access for adding sections in the submodule.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with a specific set of permissions:\n\n* Node: View published content\n* Node: (Your content type): Create new content\n* Node: (Your content type): Edit any content\n* Layout builder: (Your content type): Configure layout overrides for content items that the user can edit\n* Layout builder advanced permissions: Access Layout Builder page","aliases":["CVE-2025-8996"],"modified":"2026-09-10T03:46:01.913973395Z","published":"2025-08-13T17:33:34Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-097"}],"affected":[{"package":{"name":"drupal/layout_builder_perms","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/layout_builder_perms?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"last_affected":"2.2.0"}],"database_specific":{"constraint":"2.2.0"}}],"database_specific":{"affected_versions":"2.2.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/layout_builder_perms/DRUPAL-CONTRIB-2025-097.json"}}],"schema_version":"1.9.0","credits":[{"name":"Eelke Blok (eelkeblok)","contact":["https://www.drupal.org/u/eelkeblok"]},{"name":"Michael Whittaker (mrwhittaker)","contact":["https://www.drupal.org/u/mrwhittaker"]}]}