PT-2026-82366 · Drupal · Dxpr Builder
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DXPR Builder: The Best Editing (AI) Experience for Drupal versions 0.0.0 through 2.8.1
Description
DXPR Builder allows Forceful Browsing due to the insertion of sensitive information into sent data. In the 2.x version, the module does not sufficiently restrict access to API credentials within JavaScript settings. When AI agent features are enabled, the JSON Web Token used for licensing, user license management, AI services, and subscription metadata is exposed to all page visitors, including anonymous users, via the
drupalSettings variable.Recommendations
Update DXPR Builder: The Best Editing (AI Experience) for Drupal to a version later than 2.8.1.
As a temporary mitigation, disable the AI agent features to prevent the exposure of the API token via
drupalSettings.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dxpr Builder