Drupal · Ai Seo/Geo Analyzer · CVE-2026-15085
**Name of the Vulnerable Software and Affected Versions**
Drupal AI SEO/GEO Analyzer versions 0.0.0 through 1.1.3
**Description**
Stored Cross-site Scripting (XSS) occurs when the module generates SEO/GEO analysis reports by sending entity content, including comments, to a Large Language Model (LLM). The module converts the Markdown response from the LLM into HTML and stores it for privileged users without passing it through the filtering pipeline. A crafted prompt injection—where an attacker inserts malicious text into the content analyzed by the LLM—can cause the model to generate markup that executes scripts when the report is viewed. Prompt injection is a technique used to manipulate the output of an LLM by providing specifically crafted input.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.