meilisearch v1.48.2 版本更新介绍
发布日期: 2026-06-24
版本号: v1.48.2
Meilisearch v1.48.2 和 v1.47.1 版本修复了 CVE-2026-57823 和 CVE-2026-57824 安全漏洞。若您存在以下情况,建议更新:拥有
indexes非["*"]且actions权限超出指定列表的 API 密钥,或使用搜索租户令牌并配置了嵌入器或聊天工作区。使用 v1.48 的用户请更新至 v1.48.2,v1.47 或更低版本的用户请更新至 v1.47.1。此次更新修复了认证不当导致的权限提升漏洞(攻击者可能通过索引作用域 API 的全局操作读写系统全局状态)和信息泄露漏洞(租户令牌用户可获取超出搜索规则范围的文档有限信息)。目前未发现漏洞被利用的迹象,并向 PuH4ck3rX 致谢报告。
更新内容 (中文)
Meilisearch v1.48.2 与 Meilisearch v1.47.1 修复了 CVE-2026-57823 和 CVE-2026-57824 两个安全漏洞。若您的部署符合以下任一情况,建议进行版本更新:
- 您的 API 密钥中
indexes字段不是["*"],且actions字段包含超出以下范围的更多权限:["search", "documents.*", "indexes.*", "tasks.cancel", "tasks.delete", "tasks.get", "settings.*", "stats.*", "fields.post"] - 您使用了 搜索租户令牌,并同时配置了嵌入器或对话工作区
- 建议 Meilisearch v1.48 用户更新至 v1.48.2
- 建议 Meilisearch v1.47 及更早版本用户更新至 v1.47.1
这些版本均修复了以下漏洞:
- CVE-2026-57824:认证缺陷导致权限提升——持有索引级 API 密钥和特定操作权限的认证用户,可通过全局操作读写 Meilisearch 实例的全局状态。可能受影响的 Meilisearch Cloud 用户已提前收到通知。
- CVE-2026-57823:认证缺陷导致信息泄露——持有搜索租户令牌的用户可获取超出令牌搜索规则范围的文档存在信息,从而间接获知文档内容。
我们未检测到这些漏洞被实际利用的痕迹。
感谢 PuH4ck3rX 报告这些漏洞 :heart:
更新内容 (原始)
Meilisearch v1.48.2 and Meilisearch v1.47.1 address CVE-2026-57823 and CVE-2026-57824. We recommend updating if you are in one of the following situations:
- You have API keys where
indexesis not["*"]and whereactionscontains more permissions than:["search", "documents.*", "indexes.*", "tasks.cancel", "tasks.delete", "tasks.get", "settings.*", "stats.*", "fields.post"] - You have search tenant tokens and either an embedder or a chat workspace
- We recommend that users of Meilisearch v1.48 update to Meilisearch v1.48.2
- We recommend that users of Meilisearch v1.47 or lower update to Meilisearch v1.47.1
These versions both fix the following:
- CVE-2026-57824: Improper authentication leads to privilege escalation: an authenticated user with an index-scoped API and the appropriate set of actions could use global actions to read and write the global state of the Meilisearch instance. Possibly impacted users of Meilisearch Cloud were contacted ahead-of-time.
- CVE-2026-57823: Improper authentication leads to information disclosure: a user with a search tenant token could get some limited information about the existence of a document outside of the scope of the search rules attached to the tenant token, an indirect information about the content of the document.
We detected no trace of exploitation of these vulnerabilities.
We thank PuH4ck3rX for reporting these vulnerabilities :heart:
下载链接
- meilisearch-enterprise-linux-aarch64
- meilisearch-enterprise-linux-amd64
- meilisearch-enterprise-linux-riscv64
- meilisearch-enterprise-macos-amd64
- meilisearch-enterprise-macos-apple-silicon
- meilisearch-enterprise-windows-amd64.exe
- meilisearch-linux-aarch64
- meilisearch-linux-amd64
- meilisearch-linux-riscv64
- meilisearch-macos-amd64
- meilisearch-macos-apple-silicon
- meilisearch-openapi.json
- meilisearch-windows-amd64.exe
- meilisearch.deb