Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065
Project: Drupal CanvasDate: 2026-July-01Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Improper validationAffected versions: <1.4.2 || >=1.5.0 <1.5.2 || >=1.6.0 <1.6.1 || >=1.7.0 <1.7.1CVE IDs: CVE-2026-58587Description: The Canvas AI submodule allows you to upload image files via a custom API to use within the AI web chat.
These file uploads are insufficiently validated before being written to Drupal's temporary directory. In some cases, this may lead to cross-site scripting (XSS).Solution: Install the latest version:
- If you use the 1.4.1 version of Canvas, upgrade to 1.4.2
- If you use the 1.5.1 version of Canvas, upgrade to 1.5.2
- If you use the 1.6.0 version of Canvas, upgrade to 1.6.1
- If you use the 1.7.0 version of Canvas, upgrade to 1.7.1
Reported By:
Fixed By:
- Alex Bronstein (effulgentsia) of the Drupal Security Team
- Christian López Espínola (penyaskito)
Coordinated By:
- Juraj Nemec (poker10) of the Drupal Security Team

