Umbraco.AI
AI integration layer for Umbraco CMS, built on Microsoft.Extensions.AI.
Activity
- Latest release
- 4d ago
- Total releases
- 39
- Cadence
- ~5 days
- Last 12 months
- 39
Reach
- Stars
- 33
Details
- First release
- Feb 03, 2026
| Version | Released | |
|---|---|---|
18.3.4
patch
| ||
17.3.4
patch
| ||
18.3.3
patch
| ||
17.3.3
patch
| ||
18.4.0-rc.3
pre
| ||
17.4.0-rc.3
pre
| ||
18.4.0-rc.2
pre
| ||
17.4.0-rc.2
pre
| ||
18.4.0-rc.1
pre
| ||
17.4.0-rc.1
pre
| ||
18.3.1
patch
| ||
17.3.1
patch
| ||
18.3.0
minor
| ||
17.3.0
minor
| ||
18.2.0
minor
| ||
17.2.0
minor
| ||
18.1.1
patch
| ||
17.1.1
patch
| ||
17.1.0
minor
| ||
18.1.0
minor
| ||
18.0.0
major
| ||
17.0.0
major
| ||
1.14.0
minor
| ||
1.13.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.10.1
patch
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.10.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.9.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
GHSA-q3v2-xj35-9grx
Jul 14, 2026
Umbraco.AI discloses sensitive application configuration values
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
ImpactUnder certain configurations, a user with elevated privileges may be able to cause sensitive application configuration values, potentially including secret material such as credentials, to be disclosed. Successful exploitation could expose confidential information and, depending on what the affected installation stores in configuration, enable further compromise. Exploitation requires access to the AI section of the backoffice and a specific custom AI provider, which limits real-world exposure. PatchesPatched in 1.14.0 WorkaroundsSince the patch is a breaking change and requires a version jump, it is not recommended to try and implement a workaround. Resources
Affected versions
1.0.0
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
+ 4 more Show less
1.6.0
1.7.0
1.8.0
1.9.0
Fixed in
1.14.0
References Updated Jul 14, 2026 · Source: OSV.dev |