PT-2026-22088 · Drupal+2 · Drupal/Canvas

Bã¡Lint Klã©Ri

+5

·

Published

2026-02-25

·

Updated

2026-03-30

·

CVE-2026-3216

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal Canvas versions prior to 1.1.1
Description A Server-Side Request Forgery (SSRF) issue exists in the Drupal Canvas module. The vulnerability is exposed when the hidden canvas ai submodule is enabled, typically through Drupal Recipes or deployment scripts. The module does not adequately sanitize user-supplied data within the messages JSON payload via crafted API requests. An attacker must possess a role with the "use Drupal Canvas AI" permission to exploit this issue.
Recommendations Update to Drupal Canvas version 1.1.1 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-3216
DRUPAL-CONTRIB-2026-017

Affected Products

Drupal/Canvas