7.1

CVE-2026-25591

Exploit

New API has an SQL LIKE Wildcard Injection DoS via Token Search

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NewapiNew Api Version < 0.10.8
NewapiNew Api Version0.10.8 Updatealpha1
NewapiNew Api Version0.10.8 Updatealpha2
NewapiNew Api Version0.10.8 Updatealpha3
NewapiNew Api Version0.10.8 Updatealpha4
NewapiNew Api Version0.10.8 Updatealpha5
NewapiNew Api Version0.10.8 Updatealpha6
NewapiNew Api Version0.10.8 Updatealpha7
NewapiNew Api Version0.10.8 Updatealpha8
NewapiNew Api Version0.10.8 Updatealpha9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.387
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 7.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-943 Improper Neutralization of Special Elements in Data Query Logic

The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

https://github.com/QuantumNous/new-api/commit/3e1be18310f35d20742683ca9e4bf3bcafc173c5
Patch
https://github.com/QuantumNous/new-api/releases/tag/v0.10.8-alpha.10
Product
https://github.com/QuantumNous/new-api/security/advisories/GHSA-w6x6-9fp7-fqm4
Vendor Advisory
Exploit
Mitigation