CVE-2026-13233: OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal OpenAI Providerto a version that resolves this vulnerability.Fixed in 1.1.1 - Upgrade
Upgrade
Drupal OpenAI Providerto a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13233?
The severity of CVE-2026-13233 is categorized as moderately critical.
How do I fix CVE-2026-13233?
To fix CVE-2026-13233, update the OpenAI Provider to versions 1.2.3 or later.
What kind of vulnerability is CVE-2026-13233?
CVE-2026-13233 is identified as a Server-side Request Forgery (SSRF) vulnerability.
Which versions of OpenAI Provider are affected by CVE-2026-13233?
CVE-2026-13233 affects OpenAI Provider versions from 0.0.0 to 1.1.1 and from 1.2.0 to 1.2.2.
What impact does CVE-2026-13233 have on Drupal?
CVE-2026-13233 allows an attacker to perform Server Side Request Forgery, which can lead to unauthorized access to internal services.