All 3 CVE vulnerabilities found in one-api, with AI-generated Chinese analysis, references, and POCs.
Vendor: songquanpeng
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-81027 | one-api through 0.6.10 Missing Authorization on URL-Parameter Channel Pinning CWE-862 | 8.5 | High | 2026-08-26 |
| CVE-2026-11465 | songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic error CWE-840 | 3.1 | Low | 2026-06-07 |
| CVE-2025-3801 | songquanpeng one-api System Setting cross site scripting CWE-79 | 2.4 | Low | 2025-04-19 |
All 3 known CVE vulnerabilities affecting one-api with full Chinese analysis, references, and POCs where available.