Drupal · Ai Agents · CVE-2026-13237
**Name of the Vulnerable Software and Affected Versions**
Drupal AI Agents versions 0.0.0 through 1.1.4
Drupal AI Agents versions 1.2.0 through 1.2.5
Drupal AI Agents versions 1.3.0 through 1.3.1
**Description**
An incorrect authorization issue allows forceful browsing. Under certain conditions, the agent inherits deterministic parameters when invoking the same tool within a single request, which may result in information disclosure.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.