GHSA-q3v2-xj35-9grx

Suggest an improvement
Source
https://github.com/advisories/GHSA-q3v2-xj35-9grx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-q3v2-xj35-9grx/GHSA-q3v2-xj35-9grx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q3v2-xj35-9grx
Published
2026-07-14T19:59:45Z
Modified
2026-07-14T20:15:14Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Umbraco.AI discloses sensitive application configuration values
Details

Impact

Under certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure.

Patches

Patched in 1.14.0

Workarounds

Since the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround.

Resources

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-14T19:59:45Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

NuGet / Umbraco.AI

Package

Name
Umbraco.AI
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.AI

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.0

Affected versions

1.*
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0

Database specific

last_known_affected_version_range
"<= 1.13.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-q3v2-xj35-9grx/GHSA-q3v2-xj35-9grx.json"