Executive brief
Umbraco.AI is a package used to integrate artificial intelligence capabilities into the Umbraco content management system. A security flaw allows certain authorized users to view sensitive configuration data, such as API keys or credentials, that they should not be able to access. This could lead to the exposure of secret information and potentially allow for further unauthorized access to connected services.
Technical details
An information disclosure vulnerability (CWE-200) exists in Umbraco.AI versions 1.0.0 through 1.13.x due to insufficient scoping of configuration reference resolution. The application allows connection and context settings to resolve values from the global application configuration using a specific syntax ($Key:Path). Because this resolution was not restricted to AI-specific sections, an authenticated user with 'backoffice' access to the AI section could craft references to read arbitrary configuration values, including secrets. The fix in version 1.14.0 implements a 'default-deny' allow-list for configuration prefixes and restricts secret resolution to fields explicitly marked as sensitive.
Affected products
- Umbraco Umbraco.AI 1.0.0 - 1.13.x
Timeline
- 2026-06-04: patched: Version 1.14.0 released
- 2026-06-04: advisory: Vendor advisory published
- 2026-07-14: disclosed: GitHub Advisory published
References
- https://github.com/umbraco/Umbraco.AI/security/advisories/GHSA-q3v2-xj35-9grx
- https://github.com/umbraco/Umbraco.AI/releases/tag/2026.06.2
- https://umbraco.com/blog/security-advisory-june-4-2026-security-patch-for-umbracoai-is-now-available
- https://api.github.com/repos/umbraco/Umbraco.AI/security-advisories/GHSA-q3v2-xj35-9grx