CVE-2026-55810
Critical · CVSS 9.8Drupal Plotly.js Graphing (drupal/plotly_js) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection)
- CVSS
- 9.8
- nvd
- EPSS
- 0.16%
- 6th pct
- KEV
- No
- Class
- oss containerizable
- CWE-915
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.
Search profile — drives PoC discovery
Symbols plotly_jsdrupal/plotly_jsPlotlyJsplotly_js_graphingObject InjectionCWE-915sa-contrib-2026-050packages.drupal.org/8
Keywords CVE-2026-55810Drupal Plotly.jsplotly_js Object InjectionDrupal CWE-915Drupal sa-contrib-2026-050drupal/plotly_js exploitPlotly.js Graphing module vulnerabilityDrupal object injection PoC
Versions: 0.0.0 to 3.0.2
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/plotly_js | 0 → 3.0.2 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z