PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107308 drupal CVE debrief

A cross-site scripting vulnerability exists in the Drupal Country module's autocomplete widget due to insufficient user input escaping. This issue requires additional modules or custom code to exploit. The vulnerability affects Drupal Country module versions before 2.1.3 and 2.2.0 to 2.2.1. Defenders should verify and update the module to the latest version, especially if additional modules or custom code is used that could trigger the vulnerability. It's crucial to review and monitor additional modules and custom code for exploitation triggers and assess exposure to prioritize updates for affected versions.

Vendor
drupal
Product
country
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Drupal users and administrators who have installed the Country module, especially those using additional modules or custom code that could trigger the vulnerability, should assess their exposure and prioritize updating the module.

Why it matters

CVE-2026-107308 is a cross-site scripting vulnerability in the Drupal Country module's autocomplete widget. Defenders should verify and update the module, review additional modules and custom code, and monitor for suspicious activity.

  • Verify and update the Country module to prevent potential cross-site scripting
  • Review and monitor additional modules and custom code for exploitation triggers
  • Assess exposure and prioritize updates for affected versions

Technical summary

The Drupal Country module's autocomplete widget does not sufficiently escape user input, leading to a cross-site scripting vulnerability. This issue requires additional modules or custom code to occur and affects versions before 2.1.3 and 2.2.0 to 2.2.1. The vulnerability is confirmed in the Country module versions before 2.1.3 and 2.2.0 to 2.2.1. Official source details are limited, and further verification is required to understand the full scope of affected versions and potential exploits. Defenders should prioritize verifying and updating the Country module to the latest version, especially if additional modules or custom code is used that could trigger the vulnerability.

Defensive priority

Defenders should prioritize verifying and updating the Country module to the latest version, especially if additional modules or custom code is used that could trigger the vulnerability.

Recommended defensive actions

  • Verify and update the Country module to the latest version
  • Review additional modules and custom code for potential exploitation triggers
  • Monitor for suspicious activity related to the Country module's autocomplete widget
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is confirmed in the Country module versions before 2.1.3 and 2.2.0 to 2.2.1. Official source details are limited, and further verification is required to understand the full scope of affected versions and potential exploits.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107308 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107308

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107308 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107308

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • DRUPAL-CONTRIB-2026-211

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/DRUPAL-CONTRIB-2026-211.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://www.drupal.org/sa-contrib-2026-211

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.