meilisearch v1.47.1 版本更新介绍
发布日期: 2026-06-24
版本号: v1.47.1
Meilisearch v1.48.2 和 v1.47.1 版本修复了 CVE-2026-57823 和 CVE-2026-57824 两个安全漏洞。建议符合以下情况的用户进行更新:一是 API 密钥的索引设置为非所有(即非 ["*"]),且操作权限包含超出特定列表(包括搜索、文档管理、索引、任务取消、任务删除、任务获取、设置、统计、字段发布等操作)的范围;二是使用搜索租户令牌且配置了嵌入器或聊天工作区。对于使用 v1.48 的用户,推荐更新到 v1.48.2;对于使用 v1.47 或更低版本的用户,推荐更新到 v1.47.1。这些漏洞涉及认证不当导致的问题:CVE-2026-57824 可能导致权限升级,使认证用户能读写全局状态;CVE-2026-57823 可能导致信息泄露,允许用户获取超出搜索规则范围的文档间接信息。目前未发现漏洞被利用的痕迹,感谢 PuH4ck3rX 的报告。
更新内容 (中文)
Meilisearch v1.48.2 和 Meilisearch v1.47.1 修复了 CVE-2026-57823 和 CVE-2026-57824 两个安全漏洞。 如果您处于以下情况,我们建议进行更新:
- 您的 API 密钥中
indexes字段不是["*"],且actions字段包含的权限超出了以下范围:["search", "documents.*", "indexes.*", "tasks.cancel", "tasks.delete", "tasks.get", "settings.*", "stats.*", "fields.post"]。 - 您使用了搜索租户令牌并且同时配置了嵌入器或聊天工作区。
- 我们建议 Meilisearch v1.48 的用户更新到 Meilisearch v1.48.2。
- 我们建议 Meilisearch v1.47 或更早版本的用户更新到 Meilisearch v1.47.1。
这两个版本均修复了以下问题:
- CVE-2026-57824:不当的身份验证导致权限提升。一个拥有索引作用域 API 密钥及相应操作权限的认证用户,可以利用全局操作来读取和写入 Meilisearch 实例的全局状态。可能受影响的 Meilisearch Cloud 用户已被提前联系。
- CVE-2026-57823:不当的身份验证导致信息泄露。一个拥有搜索租户令牌的用户可以获取超出该令牌搜索规则作用域之外的文档存在性的部分有限信息,即关于文档内容的间接信息。
我们未检测到这些漏洞被利用的痕迹。
我们感谢 PuH4ck3rX 报告了这些漏洞 :heart:
更新内容 (原始)
Meilisearch v1.48.2 and Meilisearch v1.47.1 address CVE-2026-57823 and CVE-2026-57824. We recommend updating if you are in one of the following situations:
- You have API keys where
indexesis not["*"]and whereactionscontains more permissions than:["search", "documents.*", "indexes.*", "tasks.cancel", "tasks.delete", "tasks.get", "settings.*", "stats.*", "fields.post"] - You have search tenant tokens and either an embedder or a chat workspace
- We recommend that users of Meilisearch v1.48 update to Meilisearch v1.48.2
- We recommend that users of Meilisearch v1.47 or lower update to Meilisearch v1.47.1
These versions both fix the following:
- CVE-2026-57824: Improper authentication leads to privilege escalation: an authenticated user with an index-scoped API and the appropriate set of actions could use global actions to read and write the global state of the Meilisearch instance. Possibly impacted users of Meilisearch Cloud were contacted ahead-of-time.
- CVE-2026-57823: Improper authentication leads to information disclosure: a user with a search tenant token could get some limited information about the existence of a document outside of the scope of the search rules attached to the tenant token, an indirect information about the content of the document.
We detected no trace of exploitation of these vulnerabilities.
We thank PuH4ck3rX for reporting these vulnerabilities :heart:
下载链接
- meilisearch-enterprise-linux-aarch64
- meilisearch-enterprise-linux-amd64
- meilisearch-enterprise-linux-riscv64
- meilisearch-enterprise-macos-amd64
- meilisearch-enterprise-macos-apple-silicon
- meilisearch-enterprise-windows-amd64.exe
- meilisearch-linux-aarch64
- meilisearch-linux-amd64
- meilisearch-linux-riscv64
- meilisearch-macos-amd64
- meilisearch-macos-apple-silicon
- meilisearch-openapi.json
- meilisearch-windows-amd64.exe
- meilisearch.deb