Drupal Canvas
2 security fixes in one update. Drupal Canvas fixed 2 separate security bugs this week: 2 improper validation. One update covers all of them. The most serious, SA-CONTRIB-2026-066, is explained here and the full list is at the end of the card.
A person with an account could upload a dangerous file that pretends to be an image. This file could execute hidden commands that let the person read private details or alter pages on the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the web server is set up to serve uploaded files based on their actual file type.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Drupal Canvas to 1.4.2, 1.5.2, 1.6.1 or 1.7.1, whichever branch you are on.
For developers: what the fix changed
The fix updates the file upload process in `CanvasBuilder.php` to use Drupal core's `FileUploadHandlerInterface` with the `FileIsImage` validator, ensuring the uploaded file is actually an image rather than relying on the client provided MIME type.
Also in this release The release also includes built assets for the Astro hydration package.
.gitignore+2 −0modules/canvas_ai/src/Controller/CanvasBuilder.php+31 −20 fixpackages/astro-hydration/dist/FormattedText-C1aZH-9n.js+1 −0packages/astro-hydration/dist/FormattedText.js+1 −0packages/astro-hydration/dist/Stub.js+2 −0packages/astro-hydration/dist/_commonjsHelpers.js+1 −0packages/astro-hydration/dist/astro.js+4 −0packages/astro-hydration/dist/astro/server.js+0 −0packages/astro-hydration/dist/canvas-island.js+1 −0packages/astro-hydration/dist/class-variance-authority.js+1 −0packages/astro-hydration/dist/client.js+1 −0packages/astro-hydration/dist/clsx.js+1 −0
- Moderately critical · Improper validation · SA-CONTRIB-2026-066
- Moderately critical · Improper validation · SA-CONTRIB-2026-065