PatchSiren cyber security CVE debrief
CVE-2026-107308 drupal CVE debrief
A cross-site scripting vulnerability exists in the Drupal Country module's autocomplete widget due to insufficient user input escaping. This issue requires additional modules or custom code to exploit. The vulnerability affects Drupal Country module versions before 2.1.3 and 2.2.0 to 2.2.1. Defenders should verify and update the module to the latest version, especially if additional modules or custom code is used that could trigger the vulnerability. It's crucial to review and monitor additional modules and custom code for exploitation triggers and assess exposure to prioritize updates for affected versions.
- Vendor
- drupal
- Product
- country
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Drupal users and administrators who have installed the Country module, especially those using additional modules or custom code that could trigger the vulnerability, should assess their exposure and prioritize updating the module.
Why it matters
CVE-2026-107308 is a cross-site scripting vulnerability in the Drupal Country module's autocomplete widget. Defenders should verify and update the module, review additional modules and custom code, and monitor for suspicious activity.
- Verify and update the Country module to prevent potential cross-site scripting
- Review and monitor additional modules and custom code for exploitation triggers
- Assess exposure and prioritize updates for affected versions
Technical summary
The Drupal Country module's autocomplete widget does not sufficiently escape user input, leading to a cross-site scripting vulnerability. This issue requires additional modules or custom code to occur and affects versions before 2.1.3 and 2.2.0 to 2.2.1. The vulnerability is confirmed in the Country module versions before 2.1.3 and 2.2.0 to 2.2.1. Official source details are limited, and further verification is required to understand the full scope of affected versions and potential exploits. Defenders should prioritize verifying and updating the Country module to the latest version, especially if additional modules or custom code is used that could trigger the vulnerability.
Defensive priority
Defenders should prioritize verifying and updating the Country module to the latest version, especially if additional modules or custom code is used that could trigger the vulnerability.
Recommended defensive actions
- Verify and update the Country module to the latest version
- Review additional modules and custom code for potential exploitation triggers
- Monitor for suspicious activity related to the Country module's autocomplete widget
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is confirmed in the Country module versions before 2.1.3 and 2.2.0 to 2.2.1. Official source details are limited, and further verification is required to understand the full scope of affected versions and potential exploits.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107308 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107308
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107308 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107308
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
DRUPAL-CONTRIB-2026-211
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/DRUPAL-CONTRIB-2026-211.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://www.drupal.org/sa-contrib-2026-211
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.