Junglewise Threat Intelligence

CVE-2025-31692: Drupal AI Vulnerable to OS Command Injection via Optional Automator Types

CVE-2025-31692 · Severity: medium · CVSS 4 · Published 2025-04-01

Technologies: drupal/ai (Packagist), Packagist:Https://Packages.Drupal.Org/8 Drupal/Ai. Vendors: Packagist, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal AI Vulnerable to OS Command Injection via Optional Automator Types

Affected products

  • Packagist drupal/ai
  • packagist:https://packages.drupal.org/8 drupal/ai

Related threats