Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134
  • Date: Wed, 9 Sep 2026 17:14:01 +0000
  • Arc-authentication-results: i=2; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ws8wr8Gi; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=FeMNLAdC; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ws8wr8Gi; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=FeMNLAdC; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 48FBA80EC5
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org D09A480E12
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975149; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=3xjVj9f4j780E8kdORV6hTmRLjNXY2/4SAlYAMejJF4=; b=nc+ylZTkOYTAE/QyinVTJKUPnpcgKotv0xsP3yTuq9ANUl3dKIEF/GtFhMrCmblGiBxU dUrp85LzAfgPkfkR6xVgeKC5MMmX8en/juo4y/ZfBGi1kcdrzQ8NtPYt2/noHIocGsPoi dP1gSLZz9gVhkbj8uhlznUrafum3xV5X9GCq+U48y28nCyWu3yPAEYoqxE4Lzky28L9Vz PPVMH9j3mo9xeIBiqhvRCQlfaGbx9m81GVqjUiUmwMhH4o/jYN+HvJQ4l5rvV2NF7QWCP CPZk5R4FpfEsQ5EKcSEYxeoVokyNJGFwhY8y/dfpSzSQdkfFFaEnRVjJ2qctxia604A==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974043; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=Y+iWVwCIzNpyHOBm3D6RVke27d4JMIlIL2Yo5mux6NU=; b=mnSYz1rGtrduvyvngYiWt2G44QhA/aLDo8ldV7j5f/ga45SR1jUwftB75Fhc7CGY2dJk ULlJQovHf1PobHAZptaP0s4F5FgchqdLxZT0h2M4p9GrtDS/gRH6SmnsyuqiGfY+6Abed kI727AbncF+tPJzKZ13JNvTS+puIgbK4TlTJP6w0wyz+xcrjhAKGx5mrAGenirSOOFnwX WSEGYjxgzv56p+1RVU0iCb6phInKKtGprnrzmQ2s8mlNir53tbf9k/RvrUVo87k28MRzn wQmqrPmpOqKkQJajyPkCLVvfERsudOFQN+a5KsP0bcnIQVMY9TSNvEn3Zr159OYcmNQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975149; b=tdxIfk2AtQAe0ipefn4ygENn6u/dKcACnEk3JYYTOju6XTY1bmDJBS45tie4WqhMV3Rj GTefBzJ6H17JFnmxqy8nE1TH35vM7U9+QRcYazxzq8iH+yycBBv1seGP/cP+7OG+tlr56 N/VKkS4FUx1LN4nbv4EczHwu1J4FU7jpmRFHKR4vC6dcJfFRay/BJCgb23e4XS3W+Sv2i UEQfzKmMsjy6qM+6RNhwTuner72Wu+fYxI8XTTDJFDfCtyqxZM9+1WmT8b0urkevWcgE4 9ATAZeOCtbMWw/vRVwUy2X0B5KioRtPZGEFdGVDphXYWGCYw5jdsJDPQCo+ZytGNb4w==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974043; b=Y6SgacGZn6gmqPPnZRciuA8uC/Y29Lyyiwrk6tWMg3iP75Ukw9NALDPDIYK6k9+QKrcs z/d6PscyarNsMvLUz9BxN7UZI4mNm1LsLnxWMoakK7RhFbRMoKqELoEwtaO4dJrRkxPv9 SabS8UI/9ibNlKDNRTE6UnG0HhSLtlCrVpJCKz+qb3Rp8ARiZS2wmoSt+JwLqSwPqgeof PlVLiw3q3CzYpMM+sfMY40N/mTvcApUu2Bsr10RI0dGG+G7Olp/Z7AeOt07i2v64AwmlW 4E5TPg4xAiWIVXkOE9RPSdmovdaSf+UGQ8AscN7IhsmOqbJHMOt8iGIgI9kGGkWo8Fw==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/ZG5YIZBMXRSNXLFXJQGOO3GUKT6ZZDS2/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=SXhXgIfW; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ws8wr8Gi; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=FeMNLAdC; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-134

Project: amazee.ai Private AI Provider [1]
Date: 2026-September-09
Security risk: *Critical* 16 ∕ 25
AC:Complex/A:None/CI:All/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: SQL injection

Affected versions: <1.3.7 || >=1.4.0 <1.4.3
CVE IDs: CVE-2026-87936
Description: 
This module integrates amazee.ai's AI services into Drupal, including a
Postgres/pgvector vector database backend for use with Search API AI Search.

The module doesn't sufficiently sanitize filter values before using them to
build SQL queries in its Postgres/pgvector backend, allowing SQL injection.

This vulnerability is mitigated by the fact that a site must be using the
module's Postgres/pgvector vector database backend for a Search API AI Search
index, and must expose one of that index's non-string fields as a filter (for
example, through a View) that is reachable by the attacker.

Solution: 
Install the latest version:

* If you use the amazee.ai AI Provider [3] module for Drupal 1.4.x, upgrade
to ai_provider_amazeeio 1.4.3 [4].
* If you use the 1.3.x branch, upgrade to ai_provider_amazeeio 1.3.7 [5].

Reported By: 
* Matan Kotick (matank001) [6]

Fixed By: 
* Dan Lemon (dan2k3k4) [7]
* Dimitris Spachos (dspachos) [8]

Coordinated By: 
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/ai_provider_amazeeio
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ai_provider_amazeeio
[4] https://www.drupal.org/project/ai_provider_amazeeio/releases/1.4.3
[5] https://www.drupal.org/project/ai_provider_amazeeio/releases/1.3.7
[6] https://www.drupal.org/u/matank001
[7] https://www.drupal.org/u/dan2k3k4
[8] https://www.drupal.org/u/dspachos
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3620183

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang