DRUPAL-CONTRIB-2026-006

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/canvas/DRUPAL-CONTRIB-2026-006.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-006
Aliases
Published
2026-01-28T17:28:31Z
Modified
2026-09-10T03:45:24Z
Summary
[none]
Details

This Drupal Canvas module is a new visual page builder for Drupal. You can create reusable components that match your design system, drag them onto a page, edit content in place, preview changes across multiple pages, and undo mistakes with ease.

The module doesn't sufficiently validate access to Canvas Pages when they are unpublished.

This vulnerability is mitigated by the fact that Canvas Pages don't have content moderation enabled by default, and they must be unpublished after being released, and archiving is not a feature provided by the module yet.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/canvas

Package

Name
drupal/canvas
Purl
pkg:composer/drupal/canvas?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.4
Database specific
Show details
{
    "constraint": "<1.0.4"
}

Database specific

affected_versions
"<1.0.4"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/canvas/DRUPAL-CONTRIB-2026-006.json"