CVE-2025-31692
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 31, 2025
Updated: Apr 3, 2025
CWE ID 78
Summary
CVE-2025-31692 is an OS Command Injection vulnerability affecting the Drupal AI (Artificial Intelligence) module. The issue arises due to improper neutralization of special elements, enabling attackers to inject malicious operating system commands. This vulnerability can lead to serious security consequences, including system compromise. The affected versions of AI (Artificial Intelligence) are from 0.0.0 to 1.0.4. It is crucial for users to update to version 1.0.5 or higher to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- AI