Impact
Drupal AI implements a missing authorization check that allows an unauthenticated or unauthorized user to request any resource handled by the module. This flaw can expose content that should be protected, thereby compromising confidentiality. It is classified as a missing authorization weakness (CWE‑862).
Affected Systems
Any instance of the Drupal AI module that is running a version from 0.0.0 through 1.2.17, 1.3.0 through 1.3.8, or 1.4.0 through 1.4.3 is affected. The vulnerability resides in the AI (Artificial Intelligence) component distributed by Drupal and is not limited to any specific submodule or database layer.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Its CVSS score of 3.3 reflects low severity, but the flaw still permits an attacker to read protected content via forceful browsing. The likely attack vector is remote; an attacker only needs to craft requests to the vulnerable endpoints. Although widespread exploitation is unlikely, sites exposing the module to the internet could attract attempts.
OpenCVE Enrichment