Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Vulnerability Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authenticated administrator to obtain the root user's bearer token and access root-only system configuration APIs. This issue is fixed in version 1.0.0-rc.7.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
信息暴露
Vulnerability Title
QuantumNous New API 信息泄露漏洞
Vulnerability Description
QuantumNous New API是QuantumNous个人开发者的一个LLM网关和AI资产管理系统。 QuantumNous New API 1.0.0-rc.7之前版本存在信息泄露漏洞,该漏洞源于管理用户列表和用户查询API(包括GET /api/user/)在查询使用Omit("password")后序列化User模型对象,将User.AccessToken作为access_token返回,可能导致已认证管理员获取root用户的bearer token并访问root专用系统配置API。
CVSS Information
N/A
Vulnerability Type
N/A