CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-13233

Critical · CVSS 9.1

Drupal OpenAI Provider (drupal/ai_provider_openai) — Server-Side Request Forgery (SSRF)

CVSS
9.1
nvd
EPSS
0.14%
4th pct
KEV
No
Class
oss containerizable
CWE-918

Description

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.

Search profile — drives PoC discovery

Symbols ai_provider_openaidrupal/ai_provider_openaiOpenAI Providersa-contrib-2026-053CWE-918
Keywords CVE-2026-13233Drupal OpenAI Provider SSRFai_provider_openai SSRFdrupal/ai_provider_openai exploitdrupal sa-contrib-2026-053Drupal SSRF OpenAI PoCCWE-918 Drupal OpenAI
Versions: 0.0.0 to 1.1.1, 1.2.0 to 1.2.2

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Packagist:https://packages.drupal.org/8 drupal/ai_provider_openai 0 → 1.1.1
Packagist:https://packages.drupal.org/8 drupal/ai_provider_openai 1.2.0 → 1.2.2

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z