CVE-2025-31678: AI (Artificial Intelligence) - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-004
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.
Other sources
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31678?
CVE-2025-31678 is classified as a medium severity vulnerability due to missing authorization in Drupal AI.
What causes CVE-2025-31678?
CVE-2025-31678 is caused by a lack of proper authorization checks, allowing forceful browsing.
How do I fix CVE-2025-31678?
To fix CVE-2025-31678, upgrade Drupal AI to version 1.0.3 or later.
Which versions of Drupal AI are affected by CVE-2025-31678?
CVE-2025-31678 affects Drupal AI versions from 0.0.0 up to 1.0.2.
What should I do if I cannot upgrade to fix CVE-2025-31678?
If unable to upgrade, implement additional authorization checks in your application to mitigate CVE-2025-31678.