—
DRUPAL-CONTRIB-2025-119
Details
This modules provides the ability to chat with an AI Agent using a large-language model (LLM) provider for different purposes.
The module doesn’t sufficiently filter LLM responses. This leads to a cross-site scripting (XSS) vulnerability where an attacker can use prompt injections on user-generated content with the LLM as context.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/ai
Introduced in:
0Fixed in: 1.0.7Upgrade drupal/ai to 1.0.7 or newer (ecosystem packagist:https://packages.drupal.org/8).