« Volver al listado

Newapi

Newapi NEW API: vulnerabilidades y CVE

Newapi NEW API tiene 16 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses15
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71479Crítica (9.1)0.65%—17 ago 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens,…
CVE-2026-64868Alta (7.5)0.64%—17 ago 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log…
CVE-2026-64866Media (5.1)0.47%—17 ago 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole…
CVE-2026-64865Media (6)0.29%—17 ago 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay…
CVE-2026-64859Crítica (9.1)0.63%—17 ago 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken…
CVE-2026-44342Media (5.3)0.19%—9 jul 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET…
CVE-2026-33655Alta (7.7)0.44%—9 jul 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with…
CVE-2026-42339Alta (7.1)0.30%—8 may 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in…
CVE-2026-41432Alta (8.2)0.75%—8 may 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated…
CVE-2026-32879Media (4.9)0.46%—23 mar 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user…
CVE-2026-30886Media (6.5)0.36%—23 mar 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy…
CVE-2026-25802Media (5.4)0.27%—24 feb 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing…
CVE-2026-25591Alta (7.1)0.64%—24 feb 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint…
CVE-2025-62155Alta (8.5)0.28%—25 nov 2025
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the…
CVE-2025-59146Alta (8.5)0.24%—9 oct 2025
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature…
CVE-2025-55573Alta (8.8)0.42%—22 ago 2025
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1210 Exploitation of Remote Services3
  3. T1090.004 Domain Fronting2
  4. T1005 Data from Local System1
  5. T1078 Valid Accounts1
  6. T1499.001 OS Exhaustion Flood1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.