Drupal AI OS Command Injection Vulnerability

Vulnerability

A vulnerability allowing OS command injection has been identified in the Drupal AI (Artificial Intelligence) module, affecting versions 0.0.0 prior to 1.0.5. This issue arises from improper neutralization of special elements used in operating system commands, which could be exploited to execute arbitrary commands on the server.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the server where the affected Drupal AI module is installed.

Remediation

Users can update to Drupal AI version 1.0.5 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
10.0
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.