SA-CONTRIB-2026-187: Critical severity drupal/ai_ckeditor vulnerability
Published Sep 23, 2026
·Updated
This module enables you to use AI to fill in or replace text in CKEditor. The module doesn't sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.
Credit
Stef Rouschop (stefro)
Affected Software
1 affected componentFixes available
drupal/ai_ckeditor<1.4.3
1.4.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/ai_ckeditorto a version that resolves this vulnerability.Fixed in 1.4.3
Event History
Sep 23, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using the Drupal AI CKEditor module with affected AI CKEditor rules are exposed. The issue is specifically related to rules that process AI-generated content through Twig templates.
2
What could an attacker obtain by exploiting the issue?
An attacker may be able to invoke Twig functions to extract certain confidential system data.