Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6x2c-phff-wx57 | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation |
Mon, 17 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Mon, 17 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authenticated administrator to obtain the root user's bearer token and access root-only system configuration APIs. This issue is fixed in version 1.0.0-rc.7. | |
| Title | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T18:56:39.405Z
Reserved: 2026-07-20T18:31:39.291Z
Link: CVE-2026-64859
Updated: 2026-08-17T18:56:35.507Z
Status : Received
Published: 2026-08-17T16:17:22.280
Modified: 2026-08-17T19:16:33.823
Link: CVE-2026-64859
No data.
OpenCVE Enrichment
Updated: 2026-08-17T17:30:18Z
Github GHSA