Drupal · Dxpr Builder · CVE-2026-81162
**Name of the Vulnerable Software and Affected Versions**
DXPR Builder: The Best Editing (AI) Experience for Drupal versions 0.0.0 through 2.8.1
**Description**
DXPR Builder allows Forceful Browsing due to the insertion of sensitive information into sent data. In the 2.x version, the module does not sufficiently restrict access to API credentials within JavaScript settings. When AI agent features are enabled, the JSON Web Token used for licensing, user license management, AI services, and subscription metadata is exposed to all page visitors, including anonymous users, via the `drupalSettings` variable.
**Recommendations**
Update DXPR Builder: The Best Editing (AI Experience) for Drupal to a version later than 2.8.1.
As a temporary mitigation, disable the AI agent features to prevent the exposure of the API token via `drupalSettings`.