View online: https://www.drupal.org/sa-contrib-2026-053 Project: OpenAI Provider [1] Date: 2026-June-24 Security risk: *Moderately critical* 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Server-side Request Forgery Affected versions: <1.1.1 || >=1.2.0 <1.2.2 CVE IDs: CVE-2026-13233 Description: This module enables you to use OpenAI as a provider for the AI module. The module doesn't sufficiently sanitize user-supplied URLs, leading to a Server-side request forgery (SSRF) vulnerability. This vulnerability is mitigated by the fact that an attacker must have the access to change the host url and a way to generate AI-generated images. Solution: Install the latest version: * If you use the OpenAI Provider module 1.1.0, upgrade to OpenAI Provider 1.1.1 [3] * If you use the OpenAI module 1.2.1 upgrade to OpenAI Provider 1.2.2 [4] Reported By: * Kuniyoshi Noguchi (kuninogu) [5] Fixed By: * Artem Dmitriiev (a.dmitriiev) [6] * Kuniyoshi Noguchi (kuninogu) [7] * Marcus Johansson (marcus_johansson) [8] Coordinated By: * Bram Driesen (bramdriesen) [9] of the Drupal Security Team * Greg Knaddison (greggles) [10] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185237-ai_provider_openai-security/-/work_it… [11] ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/ai_provider_openai [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/ai_provider_openai/releases/1.1.1 [4] https://www.drupal.org/project/ai_provider_openai/releases/1.2.2 [5] https://www.drupal.org/u/kuninogu [6] https://www.drupal.org/u/admitriiev [7] https://www.drupal.org/u/kuninogu [8] https://www.drupal.org/u/marcus_johansson [9] https://www.drupal.org/u/bramdriesen [10] https://www.drupal.org/u/greggles [11] https://git.drupalcode.org/security/185237-ai_provider_openai-security/-/wor... [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....