CVE-2025-31693: AI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection. This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
Other sources
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/drupal/aito a version that resolves this vulnerability.Fixed in 1.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31693?
CVE-2025-31693 is categorized as a high severity vulnerability due to its potential for OS Command Injection.
How do I fix CVE-2025-31693?
To mitigate CVE-2025-31693, update Drupal AI to version 1.0.5 or later.
What versions of Drupal AI are affected by CVE-2025-31693?
CVE-2025-31693 affects all versions of Drupal AI from 0.0.0 up to but not including 1.0.5.
What type of vulnerability is CVE-2025-31693?
CVE-2025-31693 is an OS Command Injection vulnerability resulting from improper neutralization of special elements.
Who is impacted by CVE-2025-31693?
Users of Drupal AI versions prior to 1.0.5 are vulnerable to exploitation due to CVE-2025-31693.