Junglewise Threat Intelligence

CVE-2026-3573: DRUPAL-CONTRIB-2026-028 - The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM t

CVE-2026-3573 · Severity: info · Published 2026-03-11

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Ai. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM to generate HTML or Markdown and preview it in a browser.

Under certain circumstances, rendering of this HTML can lead to exposing secret communications in the context of the LLM request.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/ai

Related threats