CVE-2025-13981
EPSS 0.12%
Description
This modules provides the ability to chat with an AI Agent using a large-language model (LLM) provider for different purposes. The module doesn’t sufficiently filter LLM responses. This leads to a cross-site scripting (XSS) vulnerability where an attacker can use prompt injections on user-generated content with the LLM as context.
How to fix CVE-2025-13981
To remediate CVE-2025-13981, upgrade the affected package to a fixed version below.
- Packagist/drupal/ai—upgrade to 1.0.7 or later
Is CVE-2025-13981 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.0.7 | >= 1.1.0, < 1.1.7 | >= 1.2.0, < 1.2.4