{"id":"DRUPAL-CONTRIB-2026-061","details":"The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.  \nThe module doesn't sufficiently restrict access to direct child paragraphs of library items through API endpoints.  \nThis vulnerability is mitigated by the fact the paragraphs\\_library module must be in use and general write access to paragraphs through another module must be allowed.","aliases":["CVE-2026-13241"],"modified":"2026-09-10T03:46:02.950799826Z","published":"2026-06-24T18:43:16Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-061"}],"affected":[{"package":{"name":"drupal/paragraphs","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/paragraphs?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.21.0"}],"database_specific":{"constraint":"\u003c1.21.0"}}],"database_specific":{"affected_versions":"\u003c1.21.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/paragraphs/DRUPAL-CONTRIB-2026-061.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mustafa Ahmed (mustafa007)","contact":["https://www.drupal.org/u/mustafa007"]}]}