Drupal Synchronize Composer.json With Contrib Modules Vulnerability

Vulnerability

A critical vulnerability has been identified in the Drupal module 'Synchronize composer.json With Contrib Modules', affecting all versions. This issue arises because the project is no longer maintained, leaving a known security problem unaddressed. Users of this module are advised to uninstall it.

Impact

The vulnerability allows for a critical security risk, as all non-public data can be accessed and all data can be modified or deleted.

Remediation

Users should uninstall the 'Synchronize composer.json With Contrib Modules' module. Instructions for taking over maintainership are available on the Drupal.org maintainership guide.

Added: Oct 10, 2025, 11:17 PM
Updated: Oct 10, 2025, 11:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
4.8
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.