it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119
- Date: Wed, 2 Sep 2026 16:26:42 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/HFRHG2YQDWOEJORXVDXSEZNFC5ODW3NS/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=DFPAo80R; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=c+FGdJvI; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=MVLWTJ8d; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-119
Project: AI (Artificial Intelligence) [1]
Date: 2026-September-02
Security risk: *Moderately critical* 10 ∕ 25
AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Cross site scripting
Affected versions: <1.3.13 || >=1.4.0 <1.4.8
CVE IDs: CVE-2026-84911
Description:
This AI Chatbot module enables you to have a Chatbot using assistants to help
you with your Drupal website.
The module doesn't sufficiently sanitize for cross site scripting (XSS) when
using the structured results using legacy agent setups.
This vulnerability is mitigated by the fact that an attacker must be able to
invoke a prompt injection set via editorial content and the site must have
been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon
configuration. Any configuration setup or updated after these minor versions
are not affected.
Solution:
Install the latest version:
* If you use the AI module 1.4.7 or below upgrade to AI module 1.4.8 [3]
* If you use the AI module 1.3.12 or below upgrade to AI module 1.3.13 [4]
Reported By:
* Drew Webber (mcdruid) [5] of the Drupal Security Team
Fixed By:
* Artem Dmitriiev (a.dmitriiev) [6]
* Marcus Johansson (marcus_johansson) [7]
* Valery Lourie (valthebald) [8]
Coordinated By:
* Swan Kalata (akalata) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Drew Webber (mcdruid) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/ai
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ai/releases/1.4.8
[4] https://www.drupal.org/project/ai/releases/1.3.13
[5] https://www.drupal.org/u/mcdruid
[6] https://www.drupal.org/u/admitriiev
[7] https://www.drupal.org/u/marcus_johansson
[8] https://www.drupal.org/u/valthebald
[9] https://www.drupal.org/u/akalata
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/mcdruid
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3615882
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119, security-news, 02.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.