CVE-2025-13081
published 2025-11-18CVE-2025-13081: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects…
PriorityP336medium5.9CVSS 3.1
AVNACHPRHUINSUCHIHAN
EPSS
0.22%
12.8th percentile
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | core | >= 10.5.0 < 10.5.6 | 10.5.6 |
| drupal | core | >= 11.0.0 < 11.1.9 | 11.1.9 |
| drupal | core | >= 11.2.0 < 11.2.8 | 11.2.8 |
| drupal | core | >= 8.0.0 < 10.4.9 | 10.4.9 |
| drupal | drupal | >= 10.5.0 < 10.5.6 | 10.5.6 |
| drupal | drupal | >= 11.0.0 < 11.1.9 | 11.1.9 |
| drupal | drupal | >= 11.2.0 < 11.2.8 | 11.2.8 |
| drupal | drupal | >= 8.0.0 < 10.4.9 | 10.4.9 |
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 10.5.0 < 10.5.6 | 10.5.6 |
| drupal | drupal_core | >= 11.0.0 < 11.1.9 | 11.1.9 |
| drupal | drupal_core | >= 11.2.0 < 11.2.8 | 11.2.8 |
| drupal | drupal_core | >= 8.0.0 < 10.4.9 | 10.4.9 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
vendor_drupal·2025-11-12
CVE-2025-13081 [MEDIUM] Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
Title: Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
Vulnerability Type: Gadget chain
Description: Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. It is not directly exploitable. This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize() . There are no such known exploits in Drupal core.
Solution: Install the latest version: If you are using Drupal 10.4, update to Drupal 10.4.
GHSA
Drupal core allows Object Injection
ghsa·2025-11-18
CVE-2025-13081 [MEDIUM] CWE-502 Drupal core allows Object Injection
Drupal core allows Object Injection
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
OSV
Drupal core allows Object Injection
osv·2025-11-18
CVE-2025-13081 [MEDIUM] Drupal core allows Object Injection
Drupal core allows Object Injection
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
OSV
CVE-2025-13081: Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site
osv·2025-11-12
CVE-2025-13081 CVE-2025-13081: Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site
Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
It is not directly exploitable.
This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to `unserialize()`. There are no such known exploits in Drupal core.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published