VYPR
Moderate severityNVD Advisory· Published Jun 11, 2025· Updated Jun 11, 2025

Quick Node Block - Moderately critical - Access bypass - SA-CONTRIB-2025-064

CVE-2025-48444

Description

Missing access control in Drupal Quick Node Block before 2.0.0 allows unauthorized users to enumerate node labels.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing access control in Drupal Quick Node Block before 2.0.0 allows unauthorized users to enumerate node labels.

Vulnerability

Overview CVE-2025-48444 is a missing authorization vulnerability in the Drupal Quick Node Block module, which provides a block to display a rendered node. The module fails to check access permissions before displaying content, allowing unauthorized users to retrieve a list of labels of all nodes [2]. This issue affects versions from 0.0.0 before 2.0.0.

Exploitation

Exploitation requires no authentication or special privileges. An attacker can simply visit a page that uses the Quick Node Block and may be able to forcefully browse node labels through the block's output [1][2]. The attack is classified as forceful browsing, where an attacker can access resources without proper authorization.

Impact

An unauthorized user can enumerate the labels of all nodes on the site, which may expose sensitive information such as titles of unpublished content, node names, or other metadata. This information disclosure could aid in further attacks or violate data privacy.

Mitigation

The vulnerability is fixed in Quick Node Block version 2.0.0. Users are advised to update to the latest version immediately. No workaround is provided other than updating the module [2].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
drupal/quick_node_blockPackagist
< 2.0.02.0.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.