CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.
drupal openai appsec sigma ssrf responsible-disclosure ai-security detection-engineering openai-provider cve-2026-13233 cwe-918
-
Updated
Jul 21, 2026 - Python