VulnSea

github.com/QuantumNous/new-api vulnerabilities

CVEs whose affected-version data names the github.com/QuantumNous/new-api package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-64859Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…

MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.46%via NVD
CVE-2026-64868High· 7.5
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…

TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.47%via NVD
CVE-2026-64866Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELE…

SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.36%via NVD
CVE-2026-71479Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…

MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.52%via NVD
CVE-2026-64865Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…

SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.24%via NVD
CVE-2026-33655High· 7.7
2mo ago

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.44%via GHSA
CVE-2026-44342Medium· 5.3
2mo ago

New API is vulnerable to CSRF through user email binding

New API is vulnerable to CSRF through user email binding

SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.19%via GHSA
github.com/QuantumNous/new-api vulnerabilities (CVEs) · VulnSea