CVE-2025-31692

EPSS 0.58%

Drupal AI Vulnerable to OS Command Injection via Optional Automator Types

發布日:2025/3/5修改日:2025/12/10
也稱為:GHSA-pwjq-fx3v-8f9rDRUPAL-CONTRIB-2025-021

描述

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection. This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U

參考連結(3)