CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-q3v2-xj35-9grx: Umbraco.AI discloses sensitive application configuration values

mediumCVSS 4.9
Impact Under certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. Patches Patched in 1.14.0 Workarounds Since the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources - Announcement Blog Post: https://umbraco.com/blog/security-advisory-june-4-2026-security-patch-for-umbracoai-is-now-available/

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 4.9
Published
2026-07-14
Last updated
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-q3v2-xj35-9grx

More from GitHub Security Advisories