github.com/QuantumNous/new-api
Go14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/QuantumNous/new-apipage 1 of 1
- CVE-2025-62155HIGHCVSS 8.5EG 8.5fixed in 0.9.62025-11-25
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the existing security fix and s…
- CVE-2026-25591MEDIUMCVSS 6.5EG 6.5fixed in 0.10.8-alpha.102026-02-24
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated…
- CVE-2026-25802MEDIUMCVSS 5.4EG 5.4fixed in 0.10.8-alpha.92026-02-24
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scri…
- CVE-2026-30886MEDIUMCVSS 6.5EG 6.5fixed in 0.11.4-alpha.22026-03-23
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy endpoint (`GET /v1/videos…
- CVE-2026-32879MEDIUMCVSS 4.9EG 4.92026-03-23
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered pass…
- CVE-2026-33655HIGHCVSS 7.7EG 7.7fixed in 0.12.0-alpha.12026-07-07
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomai…
- CVE-2026-41432HIGHCVSS 7.1EG 7.1fixed in 0.12.102026-05-08
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhoo…
- CVE-2026-42339HIGHCVSS 7.1EG 7.12026-05-08
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-621…
- CVE-2026-44342MEDIUMCVSS 5.3EG 5.3fixed in 0.12.0-alpha.12026-07-07
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used …
- CVE-2026-64859CRITICALCVSS 9.1EG 9.1fixed in 1.0.0-rc.72026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token becau…
- CVE-2026-64865MEDIUMCVSS 6.0EG 6.0fixed in 1.0.0-rc.162026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because cont…
- CVE-2026-64866MEDIUMCVSS 5.1EG 5.1fixed in 1.0.0-rc.72026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE…
- CVE-2026-64868HIGHCVSS 7.5EG 7.5fixed in 1.0.0-rc.112026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies …
- CVE-2026-71479CRITICALCVSS 9.1EG 9.1fixed in 1.0.0-rc.182026-08-17
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio d…
Check whether github.com/QuantumNous/new-api is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/QuantumNous/new-api CVEs against the assets you own.
Book a Demo →