OpenAI Provider
An administrator account could supply a malicious web address to force the server to make unsafe requests. They could view restricted server responses and alter specific image generation settings. They could not access or modify every piece of information on the website.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youA site is affected if an attacker has the access right to change the host web address and a way to create artificial intelligence images.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate OpenAI Provider to 1.1.1 or 1.2.2, whichever branch you are on.
For developers: what the fix changed
The fix removes the ability to fetch generated images via URL using `file_get_contents()` in `OpenAiProvider::generateImage()`, instead forcing the API to return base64-encoded image data directly. This prevents the server from making arbitrary requests to potentially malicious URLs.
Also in this release The release also deprecates Dall-E 3 in favour of GPT Image models, updates API key validation, adds host configuration support, and updates model capabilities and defaults.
.cspell-project-words.txt+1 −2ai_provider_openai.install+23 −0ai_provider_openai.services.yml+1 −1definitions/api_defaults.yml+11 −14src/Form/OpenAiConfigForm.php+15 −5src/OpenAiChatMessageIterator.php+2 −1src/OpenAiHelper.php+15 −1src/Plugin/AiProvider/OpenAiProvider.php+110 −75 fix