github.com/QuantumNous/new-api
Go14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/QuantumNous/new-apipage 1 of 1
- CVE-2025-62155HIGHCVSS 8.5EG 8.5✓ Fixed in 0.9.62025-11-25
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the existing security fix and s…
- CVE-2026-25591MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.10.8-alpha.102026-02-24
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated…
- CVE-2026-25802MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.10.8-alpha.92026-02-24
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scri…
- CVE-2026-30886MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.11.4-alpha.22026-03-23
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy endpoint (`GET /v1/videos…
- CVE-2026-32879MEDIUMCVSS 4.9EG 4.92026-03-23
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered pass…
- CVE-2026-33655HIGHCVSS 7.7EG 7.7✓ Fixed in 0.12.0-alpha.12026-07-07
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomai…
- CVE-2026-41432HIGHCVSS 7.1EG 7.1✓ Fixed in 0.12.102026-05-08
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhoo…
- CVE-2026-42339HIGHCVSS 7.1EG 7.12026-05-08
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-621…
- CVE-2026-44342MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.12.0-alpha.12026-07-07
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used …
- CVE-2026-64859CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.0.0-rc.72026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token becau…
- CVE-2026-64865MEDIUMCVSS 6.0EG 6.0✓ Fixed in 1.0.0-rc.162026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because cont…
- CVE-2026-64866MEDIUMCVSS 5.1EG 5.1✓ Fixed in 1.0.0-rc.72026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE…
- CVE-2026-64868HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.0-rc.112026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies …
- CVE-2026-71479CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.0.0-rc.182026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio d…
Check whether github.com/QuantumNous/new-api is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/QuantumNous/new-api CVEs against the assets you own.
Start Free Scan →