CVE-2026-58587 Details
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.
A cross-site scripting (XSS) vulnerability has been identified in the Drupal Canvas AI submodule, affecting versions 0.0.0 prior to 1.4.2, 1.5.0 prior to 1.5.2, 1.6.0 prior to 1.6.1, and 1.7.0 prior to 1.7.1. The issue arises from improper validation of image file uploads via a custom API, allowing malicious scripts to be written to Drupal's temporary directory and potentially executed.
Users can upgrade to the latest version of Drupal Canvas. Those on version 1.4.1 should upgrade to 1.4.2, users on 1.5.1 should upgrade to 1.5.2, those on 1.6.0 should upgrade to 1.6.1, and users on 1.7.0 should upgrade to 1.7.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-contrib-2026-065 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal canvas project drupal canvas | < 1.4.2 >= 1.5.0, < 1.5.2 >= 1.6.0, < 1.6.1 >= 1.7.0, < 1.7.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |