CVE-2025-13983
EPSS 0.05%
Description
This module enables you to use the Tagify library to enhance text input fields with tag-style UI elements. The module does not sufficiently sanitize the `infoLabel` value under certain configurations, which can result in a cross-site scripting (XSS) vulnerability. This vulnerability is mitigated by the fact that only uncommon module configurations expose the affected `infoLabel` output, and an attacker must have user-level access to supply or manipulate this value.
How to fix CVE-2025-13983
To remediate CVE-2025-13983, upgrade the affected package to a fixed version below.
- Packagist/drupal/tagify—upgrade to 1.2.44 or later
Is CVE-2025-13983 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.2.44