{"id":"CVE-2026-64859","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-64859","summary":"New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET…","details":"New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit(\"password\"), allowing an authenticated administrator to obtain the root user's bearer token and access root-only system configuration APIs. This issue is fixed in version 1.0.0-rc.7.","published":"2026-08-17T16:17:22.280","modified":"2026-08-17T16:17:22.280","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3","label":"QuantumNous/new-api@0936e25"},"references":[{"type":"WEB","url":"https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3"},{"type":"WEB","url":"https://github.com/QuantumNous/new-api/pull/4929"},{"type":"WEB","url":"https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7"},{"type":"WEB","url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-6x2c-phff-wx57"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T16:17:22.280"}}