{"id":"CVE-2025-31695","aliases":["GHSA-p2wg-8h29-874v"],"url":"https://o3.security/vulnerability/CVE-2025-31695","summary":null,"details":"This module adds a formatter for link fields that displays the current entity with another view mode inside the link.\n\nDrupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).\n\nA separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.\n\nThis vulnerability is mitigated by that fact that an attacker would need to have the ability to add specific attributes to a Link field, which typically requires edit access via core web services, or a contrib or custom module.","published":"2025-03-19T18:52:53Z","modified":"2026-09-10T03:45:55.823592895Z","cvss":null,"epss":{"score":0.00242,"percentile":0.15379,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist:https://packages.drupal.org/8","name":"drupal/link_field_display_mode_formatter","fixedVersion":"1.6.0"}],"fix":null,"references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-024"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:45:55.823592895Z"}}