Drupal Module Security Audit: 35+ XSS, CSRF and Solr Injection Issues Fixed
The Drupal module went through a three-round security audit. More than 35 issues were found and fixed across all module files.
01 What was hardened
- XSS on AI streaming output. Streamed answers now pass through a DOMParser sanitizer.
- Solr injection. Range filters and facet values are no longer able to alter the query sent to Solr.
- CSRF. All admin write endpoints are protected.
- Safe URL generation. URLs built in CLI and cron context are generated correctly and safely.
35+ issues found and fixed across all module files over three audit rounds.