github.com
https://github.com/goalgorilla/open_social CVE-2025-31686
Open Social - Less critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-015
Description
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Open SocialBrowse Drupal / Open SocialDefault status: unaffected | CVE List | 0.0.0 to < 12.3.11 | affected |
| 12.4.0 to < 12.4.10 | affected | ||
goalgorilla/open_socialBrowse Packagist / goalgorilla/open_social | GitHub Advisory | Before 12.3.11 · Fixed in 12.3.11 | affected |
| 12.4.0 to < 12.4.10 · Fixed in 12.4.10 | affected |
References
5github.com
https://github.com/goalgorilla/open_social/commit/6830b1788616fc24fb3913ce88c5d997a363a5de github.com
https://github.com/goalgorilla/open_social/commit/6fa5181901d4be3a64793f29c6ce0c9bd535a42f nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-31686 drupal.org
https://www.drupal.org/sa-contrib-2025-015