SA-CONTRIB-2026-119: XSS
This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website. The module doesn't sufficiently sanitize for cross site scripting (XSS) when using the structured results using legacy agent setups. This vulnerability is mitigated by the fact that an attacker must be able to invoke a prompt injection set via editorial content and the site must have been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon configuration. Any configuration setup or updated after these minor versions are not affected.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/aito a version that resolves this vulnerability.Fixed in 1.4.8Fixed in 1.3.13 - Compensating control
Mitigate the XSS issue by ensuring the site is set up only with AI 1.0.x and AI Agents 1.0.x branch using the uncommon configuration where the legacy agent structured results are used.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Exposure is limited to sites using the AI Chatbot module with an AI 1.0.x and AI Agents 1.0.x legacy-agent setup that uses the uncommon affected configuration. Configurations created or updated after those minor versions are not affected.
What does an attacker need to exploit it?
An attacker must be able to invoke a prompt injection through editorial content. The vulnerable legacy-agent structured-results configuration must also be in use.