Overview
A cross-site scripting (XSS) vulnerability has been identified in the Drupal AI (Artificial Intelligence) module, posing a medium-level risk to websites using affected versions. This flaw, tracked as CVE-2025-13981, stems from improper handling of user input during web page generation, which could allow attackers to inject malicious scripts into web pages viewed by other users.
CVE Details
The vulnerability affects the AI (Artificial Intelligence) module for Drupal.
- Product: AI (Artificial Intelligence) module for Drupal
- Published: January 28, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The following versions of the AI (Artificial Intelligence) module for Drupal are impacted by this XSS vulnerability:
- Versions from 0.0.0 before 1.0.7
- Versions from 1.1.0 before 1.1.7
- Versions from 1.2.0 before 1.2.4
Users running any of these versions are advised to take immediate action to secure their installations.
Current Status
The vulnerability is currently in an “Analyzed” status, meaning it has been reviewed and confirmed. Drupal has released updates to address this issue.
Severity Level
This vulnerability has been assigned a Medium severity level. While not critical, XSS vulnerabilities can lead to significant security breaches if exploited. The impact can range from defacing a website to stealing sensitive user information, depending on the nature of the injected script and the context of its execution.
Possible Solutions
To mitigate the risk associated with CVE-2025-13981, users of the Drupal AI module should upgrade to the patched versions as soon as possible. The following versions contain the necessary fixes:
- AI (Artificial Intelligence) module version 1.0.7 or later
- AI (Artificial Intelligence) module version 1.1.7 or later
- AI (Artificial Intelligence) module version 1.2.4 or later
It is crucial to identify which branch of the module you are currently using and upgrade to the corresponding patched version or a newer stable release. Regularly updating all modules and core Drupal installations is a fundamental practice for maintaining a secure web environment.
References
https://www.drupal.org/sa-contrib-2025-119


