Impact
The vulnerability in Drupal AI Agents is a missing authorization flaw that allows forceful browsing. An attacker can access URLs that should be protected, exposing content that was intended to be hidden. This is a classic authorization bypass (CWE-862) and can lead to the disclosure of confidential information.
Affected Systems
Drupal AI Agents versions 0.0.0 through 1.1.4, 1.2.0 through 1.2.5, and 1.3.0 through 1.3.1 are affected. The issue does not apply to releases beyond 1.3.1.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity, while the EPSS score of less than 1 % shows a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote web traffic that accesses the vulnerable instance. No special privileges are required to trigger the flaw.
OpenCVE Enrichment