CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.
-
Updated
Jul 21, 2026 - Python
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.
Fix Codex request timed out / retries 5 times by downgrading WebSocket to HTTP/SSE via config.toml | 解决 Codex 重试5次和代理超时
Add a description, image, and links to the openai-provider topic page so that developers can more easily learn about it.
To associate your repository with the openai-provider topic, visit your repo's landing page and select "manage topics."