Researcher Says Claude Found and Validated Critical Drupal SQL Injection in About Ten Minutes

Security graphic showing code review moving through a layered validation process to a confirmed result. The text says "From Broad Prompt to Validated Exploit. Claude moved from code review to a working proof of concept against a Drupal module in about ten minutes."

Vulnerability reporter Matan Kotick says Anthropic's Claude found a Critical SQL injection vulnerability in Drupal's amazee.ai Private AI Provider module in about ten minutes. In a response to The DropTimes, Matan said the result went beyond a code-level finding to a working, validated proof of concept. The Drupal Security Team published the vulnerability as CVE-2026-87936 on 9 September 2026 and lists Matan under “Reported By” in SA-CONTRIB-2026-134.

Matan had said in a LinkedIn post that he asked Claude to find a vulnerability in Drupal without directing it to a particular module or code path. His response to The DropTimes clarifies that the roughly ten-minute claim covered both discovery and validation against a test environment. The DropTimes has not independently reproduced the discovery and validation process.

Asked what Claude had established by that point, Matan said the result was not limited to identifying code that appeared vulnerable.

“It went all the way to a working, validated proof of concept - not just a code-level finding.”

Matan said Claude identified the vulnerable code path, built a test environment, ran the exploit against it, and confirmed that the SQL injection worked. According to his account, the process therefore demonstrated exploitability rather than stopping at a potential vulnerability.

The Drupal Security Team says the module did not sufficiently sanitise filter values before using them to build SQL queries in its Postgres/pgvector backend. Exploitation requires a site to use that backend for a Search API AI Search index and expose one of the index's non-string fields as a filter that an attacker can reach. Versions below 1.3.7 and versions from 1.4.0 through 1.4.2 are affected, with fixes available in 1.3.7 and 1.4.3.

The advisory was updated on 11 September 2026 to Critical 17/25 with an exploit assessment of E:Proof. The Drupal Security Team said the increased score reflected publicly documented methods for developing exploits.

Asked whether his work was connected to the 11 September change, Matan told The DropTimes, “Honestly, I don't know whether the two are connected.” The advisory identifies publicly documented exploit-development methods as the reason for the higher score but does not identify the specific material that prompted the reassessment.

The DropTimes covered the vulnerability in its 10 September report on 20 contributed-project security advisories, before the 11 September risk-score update. The affected versions and corrective releases did not change with that reassessment. Sites using the affected configuration should upgrade the 1.3.x branch to 1.3.7 or the 1.4.x branch to 1.4.3.

Reference: LinkedIn (11 September 2026)

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events

Latest Opportunities