Cyber Posture

CVE-2025-31678

High

Published: 31 March 2025

Published
31 March 2025
Modified
04 June 2025
KEV Added
Patch
CVSS Score 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS Score 0.0036 57.8th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-31678 is a missing authorization vulnerability, classified under CWE-862, in the Drupal AI (Artificial Intelligence) module that enables forceful browsing. This issue affects all versions of the AI module from 0.0.0 up to but excluding 1.0.3. The vulnerability carries a CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H), indicating high severity primarily due to its potential for significant availability disruption.

Remote attackers require no privileges or user interaction and can exploit the flaw over the network with low attack complexity. Exploitation allows limited access to confidential information alongside high-impact denial of service, such as resource exhaustion or service disruption on affected Drupal sites running vulnerable AI module versions.

The official Drupal security advisory at https://www.drupal.org/sa-contrib-2025-004 details the issue and recommends updating the AI (Artificial Intelligence) module to version 1.0.3 or later as the primary mitigation.

This vulnerability occurs in a Drupal module handling artificial intelligence features, highlighting potential risks in AI-integrated web applications. No public information on real-world exploitation is available as of the CVE publication on 2025-03-31.

Details

CWE(s)
CWE-862

Affected Products

artificial intelligence project
artificial intelligence
≤ 1.0.3

AI Security Analysis

AI Category
Other Platforms
Risk Domain
Other ATLAS/OWASP Terms
OWASP Top 10 for LLMs 2025
None mapped
MITRE ATLAS Techniques
None mapped
Classification Reason
The vulnerability affects 'Drupal AI (Artificial Intelligence)', a module for integrating AI functionalities into the Drupal CMS platform, fitting under 'Other Platforms' as it is a platform-specific AI extension rather than a core framework, library, or specialized AI tool.

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Missing authorization in Drupal AI module enables forceful browsing, facilitating exploitation of a public-facing web application.

References