PT-2026-56665 · Drupal · Ai Seo/Geo Analyzer

·

CVE-2026-15085

·

Published

2026-07-08

·

Updated

2026-08-06

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal AI SEO/GEO Analyzer versions 0.0.0 through 1.1.3
Description Stored Cross-site Scripting (XSS) occurs when the module generates SEO/GEO analysis reports by sending entity content, including comments, to a Large Language Model (LLM). The module converts the Markdown response from the LLM into HTML and stores it for privileged users without passing it through the filtering pipeline. A crafted prompt injection—where an attacker inserts malicious text into the content analyzed by the LLM—can cause the model to generate markup that executes scripts when the report is viewed. Prompt injection is a technique used to manipulate the output of an LLM by providing specifically crafted input.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15085
DRUPAL-CONTRIB-2026-076

Affected Products

Ai Seo/Geo Analyzer