VulnSea

QuantumNous has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.7
Publish → KEV
Last 90 days
7 prev 0

Products

  • github.com/QuantumNous/new-api 7
7
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

QuantumNous vulnerabilities

CVEs affecting QuantumNous, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-64859Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…

MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.46%via NVD
CVE-2026-64868High· 7.5
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…

TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.47%via NVD
CVE-2026-64866Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELE…

SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.36%via NVD
CVE-2026-71479Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…

MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.52%via NVD
CVE-2026-64865Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…

SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.24%via NVD
CVE-2026-33655High· 7.7
2mo ago

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.44%via GHSA
CVE-2026-44342Medium· 5.3
2mo ago

New API is vulnerable to CSRF through user email binding

New API is vulnerable to CSRF through user email binding

SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.19%via GHSA
QuantumNous vulnerabilities (CVEs) · VulnSea