Junglewise Threat Intelligence

CVE-2026-58588: Drupal Canvas cross-site scripting via improper file validation

CVE-2026-58588 · Severity: info · CVSS 4.3 · Published 2026-07-10

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Canvas. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

Drupal Canvas is a module that allows website builders to design pages and manage content directly in the browser. A security flaw in the module's file upload system allows users to upload malicious files that bypass intended image restrictions. If a visitor accesses these files, an attacker could execute malicious scripts in the visitor's browser, potentially leading to unauthorized actions or data theft.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Drupal Canvas module due to improper neutralization of input during file uploads. The module's custom API validates file extensions but fails to verify the actual MIME type of uploaded files. An attacker can exploit this by uploading a non-image file (such as an HTML file with embedded JavaScript) disguised with an image extension. Depending on the web server configuration, the file may be served with its original MIME type, allowing the execution of arbitrary scripts in the context of the user's session. This affects versions prior to 1.4.2, 1.5.2, 1.6.1, and 1.7.1.

Affected products

  • Drupal Drupal Canvas 0.0.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, 1.7.0 to 1.7.1

Timeline

  • 2026-07-01: patched: Security release versions 1.4.2, 1.5.2, 1.6.1, and 1.7.1 published.
  • 2026-07-10: disclosed: CVE-2026-58588 published.

References

Related threats