mediumCVSS 4.9Vulnerability

GHSA-q3v2-xj35-9grx

### Impact Under certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. ### Patches Patched in 1.14.0 ### Workarounds Since the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. ### Resources * Announcement Blog Post: https://umbraco.com/blog/security-advisory-june-4-2026-security-patch-for-umbracoai-is-now-available/

Properties

ghsa_id
GHSA-q3v2-xj35-9grx
severity
medium
summary
Umbraco.AI discloses sensitive application configuration values
cvss_score
4.9
cve_id
GHSA-q3v2-xj35-9grx
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-07-14T19:59:45Z
source_url
https://github.com/advisories/GHSA-q3v2-xj35-9grx
ghsa_updated
2026-07-14T19:59:49Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]nuget/Umbraco.AI

AFFECTS (1)

[Software]nuget/Umbraco.AI

HAS_WEAKNESS (1)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

Explore deeper with Ninja Signal's threat intelligence graph