CVE-2025-13981: AI (Artificial Intelligence) - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-119
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS).This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.7, from 1.1.0 before 1.1.7, from 1.2.0 before 1.2.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13981?
CVE-2025-13981 has a moderately critical severity rating due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2025-13981?
To fix CVE-2025-13981, upgrade the Drupal AI module to a version newer than 1.0.7, 1.1.7, or 1.2.4.
What types of applications are affected by CVE-2025-13981?
CVE-2025-13981 affects the Drupal AI module, specifically versions 1.0.7, 1.1.7, and 1.2.4.
What are the risks of CVE-2025-13981?
The risks of CVE-2025-13981 include the possibility of unauthorized script execution, potentially compromising user data.
How can I prevent similar vulnerabilities like CVE-2025-13981?
To prevent similar vulnerabilities, regularly update your software and perform security audits on input handling.