Drupal Module Security Audit: 35+ XSS, CSRF and Solr Injection Issues Fixed

· Security · Improvement · All updates

The Drupal module went through a three-round security audit. More than 35 issues were found and fixed across all module files.

01 What was hardened

  • XSS on AI streaming output. Streamed answers now pass through a DOMParser sanitizer.
  • Solr injection. Range filters and facet values are no longer able to alter the query sent to Solr.
  • CSRF. All admin write endpoints are protected.
  • Safe URL generation. URLs built in CLI and cron context are generated correctly and safely.
35+ issues found and fixed across all module files over three audit rounds.
View the full changelog