amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134
View online: https://www.drupal.org/sa-contrib-2026-134 Project: amazee.ai Private AI Provider [1] Date: 2026-September-09 Security risk: *Critical* 16 ∕ 25 AC:Complex/A:None/CI:All/II:Some/E:Theoretical/TD:Default [2] Vulnerability: SQL injection Affected versions: <1.3.7 || >=1.4.0 <1.4.3 CVE IDs: CVE-2026-87936 Description: This module integrates amazee.ai's AI services into Drupal, including a Postgres/pgvector vector database backend for use with Search API AI Search. The module doesn't sufficiently sanitize filter values before using them to build SQL queries in its Postgres/pgvector backend, allowing SQL injection. This vulnerability is mitigated by the fact that a site must be using the module's Postgres/pgvector vector database backend for a Search API AI Search index, and must expose one of that index's non-string fields as a filter (for example, through a View) that is reachable by the attacker. Solution: Install the latest version: * If you use the amazee.ai AI Provider [3] module for Drupal 1.4.x, upgrade to ai_provider_amazeeio 1.4.3 [4]. * If you use the 1.3.x branch, upgrade to ai_provider_amazeeio 1.3.7 [5]. Reported By: * Matan Kotick (matank001) [6] Fixed By: * Dan Lemon (dan2k3k4) [7] * Dimitris Spachos (dspachos) [8] Coordinated By: * Bram Driesen (bramdriesen) [9] of the Drupal Security Team * Juraj Nemec (poker10) [10] of the Drupal Security Team * Jess (xjm) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/ai_provider_amazeeio [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/ai_provider_amazeeio [4] https://www.drupal.org/project/ai_provider_amazeeio/releases/1.4.3 [5] https://www.drupal.org/project/ai_provider_amazeeio/releases/1.3.7 [6] https://www.drupal.org/u/matank001 [7] https://www.drupal.org/u/dan2k3k4 [8] https://www.drupal.org/u/dspachos [9] https://www.drupal.org/u/bramdriesen [10] https://www.drupal.org/u/poker10 [11] https://www.drupal.org/u/xjm [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org