CVE-2025-13981

EPSS 0.05%
發布日:2025/12/3修改日:2025/12/10
也稱為:DRUPAL-CONTRIB-2025-119

描述

This modules provides the ability to chat with an AI Agent using a large-language model (LLM) provider for different purposes. The module doesn’t sufficiently filter LLM responses. This leads to a cross-site scripting (XSS) vulnerability where an attacker can use prompt injections on user-generated content with the LLM as context.

受影響套件(1)

參考連結(1)