Drupal · Ai · CVE-2026-13234
**Name of the Vulnerable Software and Affected Versions**
Drupal AI versions 0.0.0 through 1.2.17
Drupal AI versions 1.3.0 through 1.3.8
Drupal AI versions 1.4.0 through 1.4.3
**Description**
Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS). The module and specific submodules, including AI Automators, AI Translate, AI API Explorer, and AI Content Suggestions, enable the use of a Large Language Model (LLM) to generate HTML or Markdown for browser preview. Under certain conditions, rendering this HTML can lead to XSS or the exposure of secret communications within the context of the LLM request. This issue requires an attacker to be able to inject text into prompts to execute the attack.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.