it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134
- Date: Wed, 9 Sep 2026 17:14:01 +0000
- Arc-authentication-results: i=2; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ws8wr8Gi; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=FeMNLAdC; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ws8wr8Gi; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=FeMNLAdC; arc=none smtp.remote-ip=54.240.27.115
- Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 48FBA80EC5
- Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org D09A480E12
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975149; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=3xjVj9f4j780E8kdORV6hTmRLjNXY2/4SAlYAMejJF4=; b=nc+ylZTkOYTAE/QyinVTJKUPnpcgKotv0xsP3yTuq9ANUl3dKIEF/GtFhMrCmblGiBxU dUrp85LzAfgPkfkR6xVgeKC5MMmX8en/juo4y/ZfBGi1kcdrzQ8NtPYt2/noHIocGsPoi dP1gSLZz9gVhkbj8uhlznUrafum3xV5X9GCq+U48y28nCyWu3yPAEYoqxE4Lzky28L9Vz PPVMH9j3mo9xeIBiqhvRCQlfaGbx9m81GVqjUiUmwMhH4o/jYN+HvJQ4l5rvV2NF7QWCP CPZk5R4FpfEsQ5EKcSEYxeoVokyNJGFwhY8y/dfpSzSQdkfFFaEnRVjJ2qctxia604A==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974043; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=Y+iWVwCIzNpyHOBm3D6RVke27d4JMIlIL2Yo5mux6NU=; b=mnSYz1rGtrduvyvngYiWt2G44QhA/aLDo8ldV7j5f/ga45SR1jUwftB75Fhc7CGY2dJk ULlJQovHf1PobHAZptaP0s4F5FgchqdLxZT0h2M4p9GrtDS/gRH6SmnsyuqiGfY+6Abed kI727AbncF+tPJzKZ13JNvTS+puIgbK4TlTJP6w0wyz+xcrjhAKGx5mrAGenirSOOFnwX WSEGYjxgzv56p+1RVU0iCb6phInKKtGprnrzmQ2s8mlNir53tbf9k/RvrUVo87k28MRzn wQmqrPmpOqKkQJajyPkCLVvfERsudOFQN+a5KsP0bcnIQVMY9TSNvEn3Zr159OYcmNQ==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975149; b=tdxIfk2AtQAe0ipefn4ygENn6u/dKcACnEk3JYYTOju6XTY1bmDJBS45tie4WqhMV3Rj GTefBzJ6H17JFnmxqy8nE1TH35vM7U9+QRcYazxzq8iH+yycBBv1seGP/cP+7OG+tlr56 N/VKkS4FUx1LN4nbv4EczHwu1J4FU7jpmRFHKR4vC6dcJfFRay/BJCgb23e4XS3W+Sv2i UEQfzKmMsjy6qM+6RNhwTuner72Wu+fYxI8XTTDJFDfCtyqxZM9+1WmT8b0urkevWcgE4 9ATAZeOCtbMWw/vRVwUy2X0B5KioRtPZGEFdGVDphXYWGCYw5jdsJDPQCo+ZytGNb4w==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974043; b=Y6SgacGZn6gmqPPnZRciuA8uC/Y29Lyyiwrk6tWMg3iP75Ukw9NALDPDIYK6k9+QKrcs z/d6PscyarNsMvLUz9BxN7UZI4mNm1LsLnxWMoakK7RhFbRMoKqELoEwtaO4dJrRkxPv9 SabS8UI/9ibNlKDNRTE6UnG0HhSLtlCrVpJCKz+qb3Rp8ARiZS2wmoSt+JwLqSwPqgeof PlVLiw3q3CzYpMM+sfMY40N/mTvcApUu2Bsr10RI0dGG+G7Olp/Z7AeOt07i2v64AwmlW 4E5TPg4xAiWIVXkOE9RPSdmovdaSf+UGQ8AscN7IhsmOqbJHMOt8iGIgI9kGGkWo8Fw==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/ZG5YIZBMXRSNXLFXJQGOO3GUKT6ZZDS2/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=SXhXgIfW; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ws8wr8Gi; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=FeMNLAdC; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-134
Project: amazee.ai Private AI Provider [1]
Date: 2026-September-09
Security risk: *Critical* 16 ∕ 25
AC:Complex/A:None/CI:All/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: SQL injection
Affected versions: <1.3.7 || >=1.4.0 <1.4.3
CVE IDs: CVE-2026-87936
Description:
This module integrates amazee.ai's AI services into Drupal, including a
Postgres/pgvector vector database backend for use with Search API AI Search.
The module doesn't sufficiently sanitize filter values before using them to
build SQL queries in its Postgres/pgvector backend, allowing SQL injection.
This vulnerability is mitigated by the fact that a site must be using the
module's Postgres/pgvector vector database backend for a Search API AI Search
index, and must expose one of that index's non-string fields as a filter (for
example, through a View) that is reachable by the attacker.
Solution:
Install the latest version:
* If you use the amazee.ai AI Provider [3] module for Drupal 1.4.x, upgrade
to ai_provider_amazeeio 1.4.3 [4].
* If you use the 1.3.x branch, upgrade to ai_provider_amazeeio 1.3.7 [5].
Reported By:
* Matan Kotick (matank001) [6]
Fixed By:
* Dan Lemon (dan2k3k4) [7]
* Dimitris Spachos (dspachos) [8]
Coordinated By:
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/ai_provider_amazeeio
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ai_provider_amazeeio
[4] https://www.drupal.org/project/ai_provider_amazeeio/releases/1.4.3
[5] https://www.drupal.org/project/ai_provider_amazeeio/releases/1.3.7
[6] https://www.drupal.org/u/matank001
[7] https://www.drupal.org/u/dan2k3k4
[8] https://www.drupal.org/u/dspachos
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3620183
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.