DRUPAL-CONTRIB-2026-055

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ai/DRUPAL-CONTRIB-2026-055.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-055
Aliases
  • CVE-2026-13235
Published
2026-06-24T18:37:45Z
Modified
2026-06-24T19:15:04.332452767Z
Summary
[none]
Details

This module enables you to utilize an agent to use Drupal core actions tools with bypassed access.

Certain Drupal core actions, exposed as agent tools did not have correct access validation, and some core actions were missing associated access-level definitions.

This vulnerability is mitigated by the fact that an attacker must have access to communicate with an affected agent, the site must be configured to expose the affected tools to non-privileged users.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/ai

Package

Name
drupal/ai
Purl
pkg:composer/drupal%2Fai

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.17
Database specific
{
    "constraint": "<1.2.17"
}
Type
ECOSYSTEM
Events
Introduced
1.3.0
Fixed
1.3.8
Database specific
{
    "constraint": ">=1.3.0 <1.3.8"
}
Type
ECOSYSTEM
Events
Introduced
1.4.0
Fixed
1.4.3
Database specific
{
    "constraint": ">=1.4.0 <1.4.3"
}

Database specific

affected_versions
"<1.2.17 || >=1.3.0 <1.3.8 || >=1.4.0 <1.4.3"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ai/DRUPAL-CONTRIB-2026-055.json"