DRUPAL-CONTRIB-2026-119

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ai/DRUPAL-CONTRIB-2026-119.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-119
Aliases
  • CVE-2026-84911
Published
2026-09-02T16:26:41Z
Modified
2026-09-02T19:55:49Z
Summary
[none]
Details

This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website.

The module doesn't sufficiently sanitize for cross site scripting (XSS) when using the structured results using legacy agent setups.

This vulnerability is mitigated by the fact that an attacker must be able to invoke a prompt injection set via editorial content and the site must have been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon configuration. Any configuration setup or updated after these minor versions are not affected.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/ai

Package

Name
drupal/ai
Purl
pkg:composer/drupal/ai?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.13
Database specific
Show details
{
    "constraint": "<1.3.13"
}
Type
ECOSYSTEM
Events
Introduced
1.4.0
Fixed
1.4.8
Database specific
Show details
{
    "constraint": ">=1.4.0 <1.4.8"
}

Database specific

affected_versions
"<1.3.13 || >=1.4.0 <1.4.8"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ai/DRUPAL-CONTRIB-2026-119.json"