PT-2026-82366 · Drupal · Dxpr Builder

·

CVE-2026-81162

·

Published

2026-08-26

·

Updated

2026-09-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions DXPR Builder: The Best Editing (AI) Experience for Drupal versions 0.0.0 through 2.8.1
Description DXPR Builder allows Forceful Browsing due to the insertion of sensitive information into sent data. In the 2.x version, the module does not sufficiently restrict access to API credentials within JavaScript settings. When AI agent features are enabled, the JSON Web Token used for licensing, user license management, AI services, and subscription metadata is exposed to all page visitors, including anonymous users, via the drupalSettings variable.
Recommendations Update DXPR Builder: The Best Editing (AI Experience) for Drupal to a version later than 2.8.1. As a temporary mitigation, disable the AI agent features to prevent the exposure of the API token via drupalSettings.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81162
DRUPAL-CONTRIB-2026-112

Affected Products

Dxpr Builder