Junglewise Threat Intelligence

CVE-2026-13233: Drupal OpenAI Provider SSRF in host URL configuration

CVE-2026-13233 · Severity: info · CVSS 4.9 · Published 2026-07-10

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The OpenAI Provider module for Drupal, which allows websites to integrate with AI models like GPT-4 and DALL-E, contains a security flaw. An attacker with administrative privileges could exploit this to make the server send unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal data or be used to bypass network security controls.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Drupal OpenAI Provider module (ai_provider_openai) due to insufficient sanitization of user-supplied URLs. The flaw is located in the component responsible for handling host URLs and generating AI images. An attacker with administrative permissions to modify the host URL can force the server to make requests to arbitrary locations. This can be used to scan internal networks or access metadata services. The issue is fixed in versions 1.1.1 and 1.2.2.

Affected products

  • Drupal OpenAI Provider 0.0.0 to 1.1.1, 1.2.0 to 1.2.2

Timeline

  • 2026-06-24: advisory: Drupal security advisory SA-CONTRIB-2026-053 published
  • 2026-07-09: patched: Versions 1.1.1 and 1.2.2 released
  • 2026-07-10: disclosed: CVE-2026-13233 published to NVD

References