Vulnerabilites related to Drupal - AI (Artificial Intelligence)
CVE-2025-31678 (GCVE-0-2025-31678)
Vulnerability from cvelistv5
Published
2025-03-31 21:38
Modified
2025-04-29 15:40
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-862 - Missing Authorization
Summary
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Drupal | AI (Artificial Intelligence) |
Version: 0.0.0 ≤ |
{ "containers": { "adp": [ { "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.2, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2025-31678", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-04-29T15:40:32.282965Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-29T15:40:38.758Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "collectionURL": "https://www.drupal.org/project/ai", "defaultStatus": "unaffected", "product": "AI (Artificial Intelligence)", "repo": "https://git.drupalcode.org/project/ai", "vendor": "Drupal", "versions": [ { "lessThan": "1.0.3", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Mingsong" }, { "lang": "en", "type": "remediation developer", "value": "Scott Euser" }, { "lang": "en", "type": "remediation developer", "value": "Marcus Johansson" }, { "lang": "en", "type": "remediation developer", "value": "Andrew Belcher" }, { "lang": "en", "type": "coordinator", "value": "Greg Knaddison" }, { "lang": "en", "type": "coordinator", "value": "Juraj Nemec" }, { "lang": "en", "type": "coordinator", "value": "Dave Long" } ], "datePublic": "2025-01-22T16:50:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.\u003cp\u003eThis issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.\u003c/p\u003e" } ], "value": "Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3." } ], "impacts": [ { "capecId": "CAPEC-87", "descriptions": [ { "lang": "en", "value": "CAPEC-87 Forceful Browsing" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-862", "description": "CWE-862 Missing Authorization", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-03-31T21:38:07.302Z", "orgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "shortName": "drupal" }, "references": [ { "url": "https://www.drupal.org/sa-contrib-2025-004" } ], "source": { "discovery": "UNKNOWN" }, "title": "AI (Artificial Intelligence) - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-004", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "assignerShortName": "drupal", "cveId": "CVE-2025-31678", "datePublished": "2025-03-31T21:38:07.302Z", "dateReserved": "2025-03-31T21:30:04.615Z", "dateUpdated": "2025-04-29T15:40:38.758Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-31692 (GCVE-0-2025-31692)
Vulnerability from cvelistv5
Published
2025-03-31 21:50
Modified
2025-04-03 17:23
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Drupal | AI (Artificial Intelligence) |
Version: 0.0.0 ≤ |
{ "containers": { "adp": [ { "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2025-31692", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-03T17:21:48.256020Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-03T17:23:24.605Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "collectionURL": "https://www.drupal.org/project/ai", "defaultStatus": "unaffected", "product": "AI (Artificial Intelligence)", "repo": "https://git.drupalcode.org/project/ai", "vendor": "Drupal", "versions": [ { "lessThan": "1.0.5", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Drew Webber (mcdruid)" }, { "lang": "en", "type": "remediation developer", "value": "Marcus Johansson (marcus_johansson)" }, { "lang": "en", "type": "remediation developer", "value": "Drew Webber (mcdruid)" }, { "lang": "en", "type": "remediation developer", "value": "Michal Gow (seogow)" }, { "lang": "en", "type": "coordinator", "value": "Drew Webber (mcdruid)" } ], "datePublic": "2025-03-05T17:18:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.\u003cp\u003eThis issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.\u003c/p\u003e" } ], "value": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5." } ], "impacts": [ { "capecId": "CAPEC-88", "descriptions": [ { "lang": "en", "value": "CAPEC-88 OS Command Injection" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-78", "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-03-31T21:50:34.673Z", "orgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "shortName": "drupal" }, "references": [ { "url": "https://www.drupal.org/sa-contrib-2025-021" } ], "source": { "discovery": "UNKNOWN" }, "title": "AI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "assignerShortName": "drupal", "cveId": "CVE-2025-31692", "datePublished": "2025-03-31T21:50:34.673Z", "dateReserved": "2025-03-31T21:30:15.360Z", "dateUpdated": "2025-04-03T17:23:24.605Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-31677 (GCVE-0-2025-31677)
Vulnerability from cvelistv5
Published
2025-03-31 21:37
Modified
2025-04-29 15:42
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-352 - Cross-Site Request Forgery (CSRF)
Summary
Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Drupal | AI (Artificial Intelligence) |
Version: 1.0.0 ≤ |
{ "containers": { "adp": [ { "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2025-31677", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-01T18:22:05.638481Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-29T15:42:17.877Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "collectionURL": "https://www.drupal.org/project/ai", "defaultStatus": "unaffected", "product": "AI (Artificial Intelligence)", "repo": "https://git.drupalcode.org/project/ai", "vendor": "Drupal", "versions": [ { "lessThan": "1.0.2", "status": "affected", "version": "1.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Marcus Johansson" }, { "lang": "en", "type": "remediation developer", "value": "Marcus Johansson" }, { "lang": "en", "type": "remediation developer", "value": "Michal Gow" }, { "lang": "en", "type": "remediation developer", "value": "Kevin Quillen" }, { "lang": "en", "type": "remediation developer", "value": "Andrew Belcher" }, { "lang": "en", "type": "coordinator", "value": "Greg Knaddison" }, { "lang": "en", "type": "coordinator", "value": "Drew Webber" }, { "lang": "en", "type": "coordinator", "value": "Juraj Nemec" } ], "datePublic": "2025-01-15T15:58:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.\u003cp\u003eThis issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.\u003c/p\u003e" } ], "value": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2." } ], "impacts": [ { "capecId": "CAPEC-62", "descriptions": [ { "lang": "en", "value": "CAPEC-62 Cross Site Request Forgery" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-352", "description": "CWE-352 Cross-Site Request Forgery (CSRF)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-03-31T21:37:27.837Z", "orgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "shortName": "drupal" }, "references": [ { "url": "https://www.drupal.org/sa-contrib-2025-003" } ], "source": { "discovery": "UNKNOWN" }, "title": "AI (Artificial Intelligence) - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-003", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "assignerShortName": "drupal", "cveId": "CVE-2025-31677", "datePublished": "2025-03-31T21:37:27.837Z", "dateReserved": "2025-03-31T21:30:04.614Z", "dateUpdated": "2025-04-29T15:42:17.877Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-31693 (GCVE-0-2025-31693)
Vulnerability from cvelistv5
Published
2025-03-31 21:51
Modified
2025-04-03 17:24
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Drupal | AI (Artificial Intelligence) |
Version: 0.0.0 ≤ |
{ "containers": { "adp": [ { "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.6, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2025-31693", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-03T17:23:57.837085Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-03T17:24:33.215Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "collectionURL": "https://www.drupal.org/project/ai", "defaultStatus": "unaffected", "product": "AI (Artificial Intelligence)", "repo": "https://git.drupalcode.org/project/ai", "vendor": "Drupal", "versions": [ { "lessThan": "1.0.5", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Drew Webber (mcdruid)" }, { "lang": "en", "type": "remediation developer", "value": "Marcus Johansson (marcus_johansson)" }, { "lang": "en", "type": "remediation developer", "value": "Drew Webber (mcdruid)" }, { "lang": "en", "type": "coordinator", "value": "Drew Webber (mcdruid)" } ], "datePublic": "2025-03-05T17:27:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.\u003cp\u003eThis issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.\u003c/p\u003e" } ], "value": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027) vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5." } ], "impacts": [ { "capecId": "CAPEC-88", "descriptions": [ { "lang": "en", "value": "CAPEC-88 OS Command Injection" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-78", "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-03-31T21:51:17.459Z", "orgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "shortName": "drupal" }, "references": [ { "url": "https://www.drupal.org/sa-contrib-2025-022" } ], "source": { "discovery": "UNKNOWN" }, "title": "AI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "2c85b837-eb8b-40ed-9d74-228c62987387", "assignerShortName": "drupal", "cveId": "CVE-2025-31693", "datePublished": "2025-03-31T21:51:17.459Z", "dateReserved": "2025-03-31T21:30:25.064Z", "dateUpdated": "2025-04-03T17:24:33.215Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }