Junglewise Threat Intelligence

CVE-2026-58587: Drupal Canvas cross-site scripting in Canvas AI submodule

CVE-2026-58587 · Severity: info · CVSS 4.8 · Published 2026-07-10

Vendors: Drupal.

Executive brief

Drupal Canvas is a tool that allows site builders to design websites and manage content through a browser interface. A security flaw in its AI chat component allows users to upload malicious image files that are not properly checked. This could allow an attacker to execute unauthorized scripts in another user's browser, potentially leading to the theft of session information or unauthorized actions on the site.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Canvas AI submodule of the Drupal Canvas project. The vulnerability stems from improper neutralization of input during web page generation, specifically involving image files uploaded via a custom API for use within the AI web chat. These files are insufficiently validated before being written to the Drupal temporary directory. An attacker with low privileges could exploit this to upload a malicious file that executes arbitrary JavaScript in the context of a victim's browser session. The issue is fixed in versions 1.4.2, 1.5.2, 1.6.1, and 1.7.1.

Affected products

  • Drupal Drupal Canvas <1.4.2, >=1.5.0 <1.5.2, >=1.6.0 <1.6.1, >=1.7.0 <1.7.1

Timeline

  • 2026-07-01: patched: Security advisory and fixed versions released by Drupal.
  • 2026-07-10: disclosed: CVE published to NVD.

References

Related threats