Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-9013 Drupal AI Vulnerable to OS Command Injection via Optional Automator Types
Github GHSA Github GHSA GHSA-pwjq-fx3v-8f9r Drupal AI Vulnerable to OS Command Injection via Optional Automator Types
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Fri, 02 May 2025 00:00:00 +0900

Type Values Removed Values Added
First Time appeared Drupal
Drupal artificial Intelligence
CPEs cpe:2.3:a:drupal:artificial_intelligence:*:*:*:*:*:drupal:*:*
Vendors & Products Drupal
Drupal artificial Intelligence

Fri, 04 Apr 2025 03:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 07:00:00 +0900

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
Title AI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021
Weaknesses CWE-78
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2025-04-03T17:23:24.605Z

Reserved: 2025-03-31T21:30:15.360Z

Link: CVE-2025-31692

cve-icon Vulnrichment

Updated: 2025-04-03T17:23:17.991Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-31T22:15:21.873

Modified: 2025-05-01T14:36:25.373

Link: CVE-2025-31692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses