{"id":"DRUPAL-CONTRIB-2026-075","details":"This module enables you to use Single Directory Components in site building (views, field formatters, blocks, layouts) and it improves the Developer Experience (DX) with SDC.\n\nThe module doesn't sufficiently sanitize the markup passed to components under certain scenarios.\n\nThis vulnerability is mitigated by the fact that an attacker must be able to create or update content rendered by UI Patterns.","aliases":["CVE-2026-15084"],"modified":"2026-07-08T19:00:04.548811291Z","published":"2026-07-08T17:17:41Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-075"}],"affected":[{"package":{"name":"drupal/ui_patterns","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/ui_patterns"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.17"}],"database_specific":{"constraint":"\u003e=2.0.0 \u003c2.0.17"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ui_patterns/DRUPAL-CONTRIB-2026-075.json","affected_versions":"\u003e=2.0.0 \u003c2.0.17"}}],"schema_version":"1.7.5","credits":[{"name":"Hervé Donner (herved)","contact":["https://www.drupal.org/u/herved"]}]}