Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069
Project: ColorboxDate: 2026-July-01Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: < 2.1.5 || 2.2.0CVE IDs: CVE-2026-58591Description: The Colorbox module integrates with the Colorbox JavaScript library to display content in an overlay above the page.
The module doesn't sufficiently protect against injection of malicious JavaScript under certain scenarios.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.Solution: Install the latest version:
- If you use Colorbox 2.1.x, upgrade to: Colorbox 2.1.5
- If you use Colorbox 2.2.x, upgrade to: Colorbox 2.2.1
Reported By:
- Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By:
Coordinated By:
- Pierre Rudloff (prudloff) of the Drupal Security Team

