CVE-2026-13234
描述
The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM to generate HTML or Markdown and preview it in a browser. Under certain circumstances, rendering of this HTML can lead to Cross Site Scripting, or exposing secret communications in the context of the LLM request. This vulnerability is mitigated by the fact that an attacker must be able to inject text into prompts to create an attack.
如何修補 CVE-2026-13234
要修補 CVE-2026-13234,請將受影響套件升級到下列已修補版本。
- Packagist/drupal/ai—升級至 1.2.17 或更新版本
CVE-2026-13234 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-13234 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0, < 1.2.17 | >= 1.3.0, < 1.3.8 | >= 1.4.0, < 1.4.3