CVE-2025-31692: AI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection. This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
Other sources
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/drupal/aito a version that resolves this vulnerability.Fixed in 1.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31692?
CVE-2025-31692 has a medium severity rating due to the potential for OS Command Injection.
How do I fix CVE-2025-31692?
To fix CVE-2025-31692, you should upgrade Drupal AI to version 1.0.5 or later.
Which versions of Drupal AI are affected by CVE-2025-31692?
CVE-2025-31692 affects Drupal AI versions from 0.0.0 up to 1.0.5.
What type of vulnerability is CVE-2025-31692?
CVE-2025-31692 is classified as an OS Command Injection vulnerability.
What steps should I take if I cannot immediately update for CVE-2025-31692?
If an immediate update for CVE-2025-31692 isn't possible, implement strict input validation to mitigate the risk of OS Command Injection.