Drupal security updates, in plain English

Week of 11 March 2026

Drupal publishes security updates on Wednesdays. This week there were 2, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 1 update

Cyber Essentials expects a fix within 14 days. Do it this week.

Unpublished Node Permissions

Critical · 4,321 sites report using it · SA-CONTRIB-2026-029 · on drupal.org

This module creates access rights for each type of content to control who can see unpublished pieces of content.

A visitor without an account could see translated pieces of content that are not yet published. They could read the text of these translations. They could not change or delete the content.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Unpublished Node Permissions to 8.x-1.7.

For developers: what the fix changed

The fix updates unpublished_node_permissions_node_access_records in unpublished_node_permissions.module to iterate over all translation languages of a node and apply the unpublished node access grants per translation, including the language code in the grant. It also adds an update hook in unpublished_node_permissions.install to rebuild node access grants.

8.x-1.6 to 8.x-1.7 1 commit, 2 files.

  • unpublished_node_permissions.install +7 −0 fix
  • unpublished_node_permissions.module +45 −24 fix

Full diff, 8.x-1.6 to 8.x-1.7

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Moderately critical: 1 update

Include in your next routine update, within the month.

AI (Artificial Intelligence)

Moderately critical · 23,475 sites report using it · SA-CONTRIB-2026-028 · on drupal.org

This module connects a website to artificial intelligence services to automate tasks and create text.

A visitor without an account could see secret messages sent between the website and the artificial intelligence service. They could read this private information when the website shows a preview of generated text. They could not change any settings or alter the messages.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate AI (Artificial Intelligence) to 1.1.11 or 1.2.12, whichever branch you are on.

For developers: what the fix changed

The fix introduces a `HostnameFilter` service (`src/Service/HostnameFilter.php`) to sanitise AI-generated HTML and Markdown by removing or rewriting links and images pointing to untrusted external domains. This filter is applied to both standard and streamed chat outputs in `src/Plugin/ProviderProxy.php` and `src/OperationType/Chat/StreamedChatMessageIterator.php`, preventing data exfiltration via prompt injection.

Also in this release Added configuration options and UI for the hostname filter in the settings form, along with related schema updates and tests.

1.1.10 to 1.1.11 1 commit, 20 files including 2 tests.

  • .cspell-project-words.txt +11 −0
  • ai.install +14 −0
  • ai.module +15 −0
  • ai.services.yml +4 −1
  • config/install/ai.settings.yml +2 −0
  • config/schema/ai.schema.yml +8 −0
  • docs/developers/hostname_filter.md +122 −0
  • modules/ai_automators/src/PluginBaseClasses/Link.php +44 −26 fix
  • modules/ai_automators/src/PluginBaseClasses/RuleBase.php +7 −0 fix
  • src/AiProviderPluginManager.php +11 −1
  • src/Dto/HostnameFilterDto.php +75 −0
  • src/Form/AiSettingsForm.php +55 −0

Full diff, 1.1.10 to 1.1.11 · Full diff, 1.2.11 to 1.2.12

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.