Junglewise Threat Intelligence

CVE-2026-96392: Drupal AI CKEditor Twig template injection

CVE-2026-96392 · Severity: info · Published 2026-09-23

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The AI CKEditor module for Drupal allows administrators to use artificial intelligence to automatically fill in or modify text within the CKEditor rich-text editor. The module fails to properly block Twig template injection attacks, allowing attackers to use Twig template functions to extract sensitive system data such as configuration details or internal variables.

Technical details

The module has insufficient mitigation of Twig template injection vulnerabilities in certain AI CKEditor rules, permitting attackers to inject and execute Twig template functions. This vulnerability requires user interaction (an authenticated user with permissions to use the affected AI CKEditor rules) and enables information disclosure of confidential system data through template function evaluation. A patch is available in version 1.4.3.

Affected products

  • Drupal AI CKEditor <1.4.3

Timeline

  • 2026-09-23: disclosed

References