Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.
Problem types
CWE-345: Insufficient Verification of Data Authenticity
CWE-1188: Insecure Default Initialization of Resource
CWE-863: Incorrect Authorization
Product status
References
github.com/...ew-api/security/advisories/GHSA-xff3-5c9p-2mr4
github.com/QuantumNous/new-api/releases/tag/v0.12.10