DRUPAL-CONTRIB-2026-112

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/dxpr_builder/DRUPAL-CONTRIB-2026-112.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-112
Aliases
  • CVE-2026-81162
Published
2026-08-26T17:40:40Z
Modified
2026-08-26T22:30:05.519147750Z
Summary
[none]
Details

The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata.

The 2.x version of the module does not sufficiently restrict access to API credentials in JavaScript settings. When AI agent features are enabled, the token is exposed to all page visitors (including anonymous users) via drupalSettings.

This vulnerability is mitigated by the fact that a site must have DXPR Builder AI features enabled and configured with an API token.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/dxpr_builder

Package

Name
drupal/dxpr_builder
Purl
pkg:composer/drupal/dxpr_builder?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.1
Database specific
Show details
{
    "constraint": "<2.8.1"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/dxpr_builder/DRUPAL-CONTRIB-2026-112.json"
affected_versions
"<2.8.1"