Drupal security updates, in plain English · Module

Drupal Canvas

11,747 sites report using it · on drupal.org · 3 security updates explained here

This module allows people to build their website design in a browser and upload image files.

Below is every security update for Drupal Canvas that this site has covered, newest first. Each one says who could exploit it, whether it applies to your site, how urgent it is, and what to tell your developer. If your site uses this module and you are not sure which version, that is the first question to ask whoever looks after it.

Drupal Canvas

Moderately critical · 11,747 sites report using it · 2 security fixes · Week of 1 July 2026

2 security fixes in one update. Drupal Canvas fixed 2 separate security bugs this week: 2 improper validation. One update covers all of them. The most serious, SA-CONTRIB-2026-066, is explained here and the full list is at the end of the card.

A person with an account could upload a dangerous file that pretends to be an image. This file could execute hidden commands that let the person read private details or alter pages on the website.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if the web server is set up to serve uploaded files based on their actual file type.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal Canvas to 1.4.2, 1.5.2, 1.6.1 or 1.7.1, whichever branch you are on.

For developers: what the fix changed

This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-066, the most serious of them.

The fix updates the file upload process in `CanvasBuilder.php` to use Drupal core's `FileUploadHandlerInterface` with the `FileIsImage` validator, ensuring the uploaded file is actually an image rather than relying on the client provided MIME type.

Also in this release The release also includes built assets for the Astro hydration package.

1.4.1 to 1.4.2 3 commits, 42 files.

  • .gitignore +2 −0
  • modules/canvas_ai/src/Controller/CanvasBuilder.php +31 −20 fix
  • packages/astro-hydration/dist/FormattedText-C1aZH-9n.js +1 −0
  • packages/astro-hydration/dist/FormattedText.js +1 −0
  • packages/astro-hydration/dist/Stub.js +2 −0
  • packages/astro-hydration/dist/_commonjsHelpers.js +1 −0
  • packages/astro-hydration/dist/astro.js +4 −0
  • packages/astro-hydration/dist/astro/server.js +0 −0
  • packages/astro-hydration/dist/canvas-island.js +1 −0
  • packages/astro-hydration/dist/class-variance-authority.js +1 −0
  • packages/astro-hydration/dist/client.js +1 −0
  • packages/astro-hydration/dist/clsx.js +1 −0

Full diff, 1.4.1 to 1.4.2 · Full diff, 1.5.1 to 1.5.2 · Full diff, 1.6.0 to 1.6.1 · Full diff, 1.7.0 to 1.7.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Drupal Canvas

Moderately critical · 11,747 sites report using it · SA-CONTRIB-2026-017 · on drupal.org · Week of 25 February 2026

The module does not properly clean data sent in certain requests. Someone could use this to discover hidden system details. They could not alter any information.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if the hidden artificial intelligence sub module is enabled and an attacker has an account with the access right to use it.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal Canvas to 1.1.1.

For developers: what the fix changed

The fix updates CanvasBuilder.php to strictly validate that the provided file source is a base64 encoded JPEG or PNG data URI and uses base64_decode instead of file_get_contents, preventing server side request forgery.

1.1.0 to 1.1.1 1 commit, 1 file.

  • modules/canvas_ai/src/Controller/CanvasBuilder.php +3 −4 fix

Full diff, 1.1.0 to 1.1.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Drupal Canvas

Moderately critical · 11,747 sites report using it · SA-CONTRIB-2026-006 · on drupal.org · Week of 28 January 2026

The module does not correctly check access rights for pages that are not published. Anyone visiting the site could see the content of these hidden pages. They could not change any information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if a page built with this tool has been published and then unpublished.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal Canvas to 1.0.4.

For developers: what the fix changed

Updates `checkAccess` in `src/Entity/PageAccessControlHandler.php` to ensure that users with only the 'access content' permission can only view published pages.

Also in this release Version bumps in package files and updated tests.

1.0.3 to 1.0.4 2 commits, 4 files including 1 test.

  • src/Entity/PageAccessControlHandler.php +12 −3 fix
  • ui/package-lock.json +2 −2
  • ui/package.json +1 −1

Full diff, 1.0.3 to 1.0.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.