Vulnerability Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing an attacker to trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth identity in deployments where session cookies could be sent on cross-site navigations. This issue is fixed in version 0.12.0-alpha.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Newapi | New Api | < 0.12.0 |
Related Weaknesses (CWE)
References
- https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e5Patch
- https://github.com/QuantumNous/new-api/releases/tag/v0.12.0-alpha.1Release Notes
- https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9mThird Party Advisory
FAQ
What is CVE-2026-44342?
CVE-2026-44342 is a vulnerability with a CVSS score of 5.3 (MEDIUM). New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bi...
How severe is CVE-2026-44342?
CVE-2026-44342 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44342?
Check the references section above for vendor advisories and patch information. Affected products include: Newapi New Api.