{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/openai-provider--1.2.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":3.3,"id":"CVE-2026-13233"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenAI Provider (\u003c 1.1.1)","OpenAI Provider (\u003c 1.2.2)"],"_cs_severities":["low"],"_cs_tags":["SSRF","file-read","Drupal","CVE","web-application"],"_cs_type":"advisory","_cs_vendors":["Drupal"],"content_html":"\u003cp\u003eA public exploit has been released on Sploitus for CVE-2026-13233, a moderately critical Server-Side Request Forgery (SSRF) vulnerability affecting the Drupal OpenAI Provider (\u003ccode\u003eai_provider_openai\u003c/code\u003e) module. This flaw arises from insufficient input validation, where the module fetches URLs contained in the upstream API response without proper scheme allowlisting. An attacker can compromise or configure a malicious upstream AI API proxy/gateway to respond with crafted URLs, including \u003ccode\u003efile://\u003c/code\u003e schemes or internal network addresses. This allows for sensitive local file reads, such as \u003ccode\u003e/etc/hostname\u003c/code\u003e or \u003ccode\u003esettings.php\u003c/code\u003e (potentially exposing database credentials), and can facilitate access to internal network services like cloud instance metadata endpoints (e.g., \u003ccode\u003e169.254.169.254\u003c/code\u003e). While the publicly released reproducer is \u0026quot;safe\u0026quot; and sandbox-only, the availability of detailed technical information and a confirmed defect mechanism significantly elevates the risk for unpatched Drupal deployments, which remain vulnerable in the wild. The vulnerability was reported privately and fixed in versions 1.1.1 and 1.2.2.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker compromises or controls an AI API proxy/gateway configured as the upstream for a vulnerable Drupal OpenAI Provider module.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates an image generation or similar request via the Drupal module, which triggers a call to the configured upstream AI API.\u003c/li\u003e\n\u003cli\u003eThe vulnerable Drupal OpenAI Provider module sends a request to the attacker-controlled upstream AI API.\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled upstream API responds with a specially crafted URL (e.g., \u003ccode\u003efile:///path/to/sensitive/file\u003c/code\u003e or \u003ccode\u003ehttp://internal-ip/service\u003c/code\u003e) embedded within its response.\u003c/li\u003e\n\u003cli\u003eThe Drupal OpenAI Provider module, lacking proper scheme allowlisting, attempts to fetch content from the crafted URL provided in the upstream response.\u003c/li\u003e\n\u003cli\u003eThe Drupal server performs a local file read (e.g., \u003ccode\u003e/etc/hostname\u003c/code\u003e, \u003ccode\u003esettings.php\u003c/code\u003e, \u003ccode\u003e/etc/passwd\u003c/code\u003e) or an internal network request (SSRF) using the module's privileges.\u003c/li\u003e\n\u003cli\u003eThe content of the sensitive file or the response from the internal service is retrieved by the Drupal module.\u003c/li\u003e\n\u003cli\u003eThe attacker then extracts the sensitive information (e.g., database credentials, internal network configuration) from the Drupal module's processing output or logs.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13233 leads to significant information disclosure. Attackers can read arbitrary local files on the Drupal server, including critical configuration files like \u003ccode\u003esettings.php\u003c/code\u003e, which often contain database credentials, API keys, and other sensitive information. Furthermore, the SSRF capability allows access to internal network resources, potentially exposing cloud instance metadata (e.g., AWS IMDS \u003ccode\u003e169.254.169.254\u003c/code\u003e), internal services, or other systems not directly exposed to the internet. This could enable further lateral movement or privilege escalation within the compromised environment. The vulnerability is rated \u0026quot;moderately critical\u0026quot; by Drupal, indicating a significant risk to confidentiality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Drupal OpenAI Provider module to version 1.1.1 or 1.2.2 to patch CVE-2026-13233.\u003c/li\u003e\n\u003cli\u003eDeploy the \u003ccode\u003eDetect Potential Drupal OpenAI Provider SSRF to IMDS or RFC1918\u003c/code\u003e Sigma rule to your SIEM to identify anomalous outbound network connections from web server processes to internal IP ranges.\u003c/li\u003e\n\u003cli\u003eDeploy the \u003ccode\u003eDetect Drupal OpenAI Provider Local File Read of Sensitive Files\u003c/code\u003e Sigma rule to your SIEM to detect web server processes attempting to read sensitive system or configuration files like \u003ccode\u003esettings.php\u003c/code\u003e or \u003ccode\u003e/etc/hostname\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive host auditing (e.g., auditd on Linux, EDR) to monitor and log sensitive file access attempts by web processes.\u003c/li\u003e\n\u003cli\u003eEnsure proxy and EDR solutions are configured to log and alert on egress to \u003ccode\u003e169.254.169.254\u003c/code\u003e and RFC1918 ranges, especially when originating from web server processes.\u003c/li\u003e\n\u003cli\u003eImplement enhanced application audit logging for AI integrations to record \u003ccode\u003e{request_id, actor, target_url, scheme, resolved_ip, content_type}\u003c/code\u003e for all fetch operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T10:02:13Z","date_published":"2026-07-21T10:02:13Z","id":"https://feed.craftedsignal.io/briefs/2026-07-drupal-openai-ssrf/","summary":"A moderately critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-13233, in the Drupal OpenAI Provider (`ai_provider_openai`) module allows attackers to achieve local file reads or access internal network services by manipulating the upstream AI API response, with a public exploit now available.","title":"Drupal OpenAI Provider Module Vulnerable to Server-Side Request Forgery and Local File Read (CVE-2026-13233)","url":"https://feed.craftedsignal.io/briefs/2026-07-drupal-openai-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenAI Provider (\u003c 1.2.2)","version":"https://jsonfeed.org/version/1.1"}