Drupal AI SEO Link Advisor Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability exists in the Drupal AI SEO Link Advisor module, affecting versions prior to 1.0.6. The vulnerability arises because the module does not properly sanitize user-supplied URLs, allowing for unauthorized requests to be made from the server.

Impact

Exploitation of this vulnerability allows for server-side request forgery, where an attacker can manipulate the server to make requests on their behalf, potentially accessing internal resources or services.

Remediation

Users of the AI SEO Link Advisor module should upgrade to version 1.0.6.

Added: Aug 15, 2025, 5:18 PM
Updated: Aug 15, 2025, 5:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.4
exploitability
5.2
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.