AI Agents
2 security fixes in one update. AI Agents fixed 2 separate security bugs this week: 1 information disclosure, 1 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-057, is explained here and the full list is at the end of the card.
Anyone without logging in could cause an artificial intelligence agent to reveal hidden details when it uses the same tool multiple times in one request. They could view restricted agent configurations and alter certain automated tasks. They could not access or modify every piece of information on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AI Agents to 1.1.4, 1.2.5 or 1.3.1, whichever branch you are on.
For developers: what the fix changed
The fix clones the context definition in `AiAgentEntityWrapper::setToolUsageLimits` to prevent mutating the shared cached definition across agent instances, which stops parameters from being inherited. It also adds field-level access checks to `ContentEntitySeeder`, `GetCurrentContentEntityValues`, and `ListContentEntities` to ensure users have the appropriate view or edit permissions.
Also in this release The release also updates regex constraints to use named arguments, changes token replacement to not escape HTML markup, adds a logger channel, and removes some tests.
ai_agents.services.yml+4 −1composer.json+1 −1src/Plugin/AiFunctionCall/ContentEntitySeeder.php+5 −0 fixsrc/Plugin/AiFunctionCall/CreateContentType.php+1 −1src/Plugin/AiFunctionCall/EditContentType.php+1 −1src/Plugin/AiFunctionCall/GetCurrentContentEntityValues.php+8 −1 fixsrc/Plugin/AiFunctionCall/ListContentEntities.php+12 −3 fixsrc/Plugin/AiFunctionCall/ModifyVocabulary.php+1 −1src/PluginBase/AiAgentEntityWrapper.php+27 −2 fixsrc/PluginManager/AiAgentManager.php+5 −1
- Moderately critical · Information disclosure, Access bypass · SA-CONTRIB-2026-057
- Less critical · Access bypass · SA-CONTRIB-2026-056