Junglewise Threat Intelligence

CVE-2026-84911: Drupal AI module cross-site scripting in legacy agent setup

CVE-2026-84911 · Severity: info · Published 2026-09-02

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Ai. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Drupal AI module, which provides chatbot functionality to assist with website management, contains a cross-site scripting (XSS) vulnerability in its structured results feature when using legacy agent configurations. An attacker with editorial content access can inject malicious prompts that execute JavaScript in users' browsers, potentially compromising site security. The risk is limited to sites running specific older versions (AI 1.0.x and AI Agents 1.0.x) with uncommon configurations; updated or newer installations are unaffected.

Technical details

The vulnerability is an insufficient input sanitization flaw in the structured results processing of legacy agent setups, allowing reflected or stored XSS via prompt injection. Attack requires both editorial content creation privileges and the presence of AI module versions prior to 1.3.13 or 1.4.0–1.4.7 configured with the legacy 1.0.x agent branch in a non-standard setup. Patched versions (1.3.13 and 1.4.8+) have been released and eliminate the vulnerability.

Affected products

  • Drupal AI < 1.3.13, >= 1.4.0 < 1.4.8

Timeline

  • 2026-09-02: disclosed

References

Related threats