PT-2026-64454 · Nuget · Umbraco.Ai

Publicado

2026-07-14

·

Atualizado

2026-07-14

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Impact

Under certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure.

Patches

Patched in 1.14.0

Workarounds

Since the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround.

Resources

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-Q3V2-XJ35-9GRX

Produtos afetados

Umbraco.Ai