Packagist (Composer) package
drupal/ai
pkg:composer/drupal/ai
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-31693 | — | < 1.0.5 | 1.0.5 | Mar 31, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5. | ||
| CVE-2025-31692 | — | < 1.0.5 | 1.0.5 | Mar 31, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5. | ||
| CVE-2025-31678 | — | < 1.0.3 | 1.0.3 | Mar 31, 2025 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3. | ||
| CVE-2025-31677 | — | >= 1.0.0, < 1.0.2 | 1.0.2 | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2. |
- CVE-2025-31693Mar 31, 2025affected < 1.0.5fixed 1.0.5
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
- CVE-2025-31692Mar 31, 2025affected < 1.0.5fixed 1.0.5
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
- CVE-2025-31678Mar 31, 2025affected < 1.0.3fixed 1.0.3
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.
- CVE-2025-31677Mar 31, 2025affected >= 1.0.0, < 1.0.2fixed 1.0.2
Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.