漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
New API: Integer overflow in quota billing yields negative charges (self-crediting)
Vulnerability Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
QuantumNous New API 数字错误漏洞
Vulnerability Description
QuantumNous New API是QuantumNous个人开发者的一个LLM网关和AI资产管理系统。 QuantumNous New API 1.0.0-rc.18之前版本存在数字错误漏洞,该漏洞源于common/quota_math.go及相关结算路径中的转换溢出问题,用户可控制的image n、video seconds and duration、max_tokens、max_completion_tokens、maxOutputTokens、audio duration及账单表达式数量可导致
CVSS Information
N/A
Vulnerability Type
N/A