Impact
The OpenAI Provider module for Drupal contains a server‑side request forgery flaw that allows the server to perform arbitrary outbound HTTP requests. This vulnerability is identified as CWE‑918.
Affected Systems
Drupal installations that include the OpenAI Provider module are impacted. The vulnerability exists in module versions from 0.0.0 through 1.1.1 and again in releases 1.2.0 through 1.2.2; versions before 0.0.0 and after 1.2.2 are not affected.
Risk and Exploitability
The CVSS score of 3.3 indicates a low overall severity, and the EPSS score of <1% reflects a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Although the flaw is low severity, the presence of server‑side request forging means that if an attacker can supply input to the module, they may be able to direct the Drupal server to arbitrary external destinations.
OpenCVE Enrichment