SA-CONTRIB-2026-120: Critical severity drupal/ai vulnerability
This submodule AI Translate enables you to automatically translate entities. The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/aito a version that resolves this vulnerability.Fixed in 1.4.8Fixed in 1.3.13
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who can perform the AI translation operation may be able to bypass access checks for the entity being translated, its related fields, or referenced entities when those items have different access levels than the parent entity.
Does this issue grant general access to protected content?
No. The permission bypass applies only during the translate operation and does not grant unwarranted read or update access to the affected entities.
Which content relationships are relevant when assessing exposure?
Assess entities translated through AI Translate that include related fields or referenced entities, especially where those related items have access restrictions different from the parent entity.