Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076
  • Date: Wed, 8 Jul 2026 17:18:40 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/IFWKI72ESCPR5KXKA5OSNIION7GCVBHS/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=e07PMbTt; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b="R/1mRGZr"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=SJvNwkH3; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp1.osuosl.org 05C4183B39
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 040DA400AD
  • Dmarc-filter: OpenDMARC Filter v1.4.2 smtp2.osuosl.org 040DA400AD
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-076

Project: AI SEO/GEO Analyzer [1]
Date: 2026-July-08
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Cross-site Scripting

Affected versions: <1.1.3
CVE IDs: CVE-2026-15085
Description: 
The AI SEO/GEO Analyzer module generates SEO/GEO analysis reports by sending
content of an entity (including its comments) to an LLM, then converts the
model's Markdown response to HTML and stores it for display to privileged
users.

The generated HTML was rendered without passing through Drupal's filtering
pipeline, so it relied on the LLM output being safe. Under certain
circumstances a crafted prompt injection — planted in content that is
included in the analysis — can cause the LLM to emit markup that results in
stored Cross-site Scripting when the report is later viewed.

This vulnerability is mitigated by the fact that an attacker must be able to
inject text into the content that is sent to the LLM, and that prompt
injection is non-deterministic and not guaranteed to succeed on a given
attempt.

Solution: 
Install the latest version:

* If you use the AI SEO/GEO Analyzer module 1.1.x, upgrade to ai_seo 1.1.3
[3]

Reported By: 
* Drew Webber (mcdruid) [4] of the Drupal Security Team

Fixed By: 
* Juhani Väätäjä (j-vee) [5]

Coordinated By: 
* Greg Knaddison (greggles) [6] of the Drupal Security Team
* Drew Webber (mcdruid) [7] of the Drupal Security Team

Security
issue: 
https://git.drupalcode.org/security/185231-ai_seo-security/-/work_items/1
[8]
------------------------------------------------------------------------------
Contribution record [9]

[1] https://www.drupal.org/project/ai_seo
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ai_seo/releases/1.1.3
[4] https://www.drupal.org/u/mcdruid
[5] https://www.drupal.org/u/j-vee
[6] https://www.drupal.org/u/greggles
[7] https://www.drupal.org/u/mcdruid
[8] https://git.drupalcode.org/security/185231-ai_seo-security/-/work_items/1
[9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3609093

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076, security-news, 08.07.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang