-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/ai | composer | < 1.0.5 | 1.0.5 |
The vulnerability explicitly involves unsanitized input in shell commands within AI Automators. Drupal's plugin architecture would implement different automator types as plugins, with ShellCommand being a likely candidate. The execute() methods would be the execution points where user-controlled data enters system commands. While exact patch details are unavailable, the advisory's technical description and standard Drupal patterns strongly suggest these entry points.
Ongoing coverage of React2Shell