Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jurriaanroelofs

#50262of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2026-82366
5.3
2026-08-26
Drupal · Dxpr Builder · CVE-2026-81162
**Name of the Vulnerable Software and Affected Versions** DXPR Builder: The Best Editing (AI) Experience for Drupal versions 0.0.0 through 2.8.1 **Description** DXPR Builder allows Forceful Browsing due to the insertion of sensitive information into sent data. In the 2.x version, the module does not sufficiently restrict access to API credentials within JavaScript settings. When AI agent features are enabled, the JSON Web Token used for licensing, user license management, AI services, and subscription metadata is exposed to all page visitors, including anonymous users, via the `drupalSettings` variable. **Recommendations** Update DXPR Builder: The Best Editing (AI Experience) for Drupal to a version later than 2.8.1. As a temporary mitigation, disable the AI agent features to prevent the exposure of the API token via `drupalSettings`.