Drupal core – Moderately critical – Gadget chain – SA-CORE-2025-006
Project: Drupal coreDate: 2025-November-12Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Gadget chainAffected versions: >= 8.0.0 < 10.4.9 || >= 10.5.0 < 10.5.6 || >= 11.0.0 < 11.1.9 || >= 11.2.0 < 11.2.8CVE IDs: CVE-2025-13081Description: Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called “gadget chain” presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
It is not directly exploitable.
This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize(). There are no such known exploits in Drupal core.Solution: Install the latest version:
If you are using Drupal 10.4, update to Drupal 10.4.9.
If you are using Drupal 10.5, update to Drupal 10.5.6.
If you are using Drupal 11.1, update to Drupal 11.1.9.
If you are using Drupal 11.2, update to Drupal 11.2.8.
Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)Reported By:
anzuukino
Fixed By:
Anna Kalata (akalata), provisional member of the Drupal Security Team
catch (catch) of the Drupal Security Team
Neil Drumm (drumm) of the Drupal Security Team
Greg Knaddison (greggles) of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security Team
Ra Mänd (ram4nd), provisional member of the Drupal Security Team
Jess (xjm) of the Drupal Security Team
Coordinated By:
catch (catch) of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security TeamSecurity advisoriesRead More