PT-2026-22088 · Drupal+2 · Drupal/Canvas
Bã¡Lint Klã©Ri
+5
·
Published
2026-02-25
·
Updated
2026-03-30
·
CVE-2026-3216
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Canvas versions prior to 1.1.1
Description
A Server-Side Request Forgery (SSRF) issue exists in the Drupal Canvas module. The vulnerability is exposed when the hidden
canvas ai submodule is enabled, typically through Drupal Recipes or deployment scripts. The module does not adequately sanitize user-supplied data within the messages JSON payload via crafted API requests. An attacker must possess a role with the "use Drupal Canvas AI" permission to exploit this issue.Recommendations
Update to Drupal Canvas version 1.1.1 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal/Canvas