#VU118485 Deserialization of Untrusted Data in Drupal - CVE-2025-13081
Published: November 13, 2025
Drupal
Drupal
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data if another vulnerability is present. A remote administrator can pass specially crafted data to the application and execute arbitrary code on the target system.