{"id":"DRUPAL-CONTRIB-2025-021","details":"The AI Automators module (a submodule of AI) enables you to create different automated tasks that fills out field data using LLM outputs.\n\nThe module doesn't sufficiently sanitize input before passing it to the underlying shell as part of a command for execution, allowing an attacker to run arbitrary commands.\n\nThe vulnerability exists in optional Automator Types which are part of the optional AI Automators (sub)module.\n\nThe AI module is included in Drupal CMS.","aliases":["CVE-2025-31692","GHSA-pwjq-fx3v-8f9r"],"modified":"2026-09-10T03:45:05.773238473Z","published":"2025-03-05T17:18:25Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-021"}],"affected":[{"package":{"name":"drupal/ai","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/ai?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.5"}],"database_specific":{"constraint":"\u003c1.0.5"}}],"database_specific":{"affected_versions":"\u003c1.0.5","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ai/DRUPAL-CONTRIB-2025-021.json"}}],"schema_version":"1.9.0","credits":[{"name":"Drew Webber (mcdruid)","contact":["https://www.drupal.org/u/mcdruid"]}]}