Moderate severityNVD Advisory· Published Jul 9, 2026· Updated Jul 10, 2026
New API CSRF in email and WeChat account binding endpoints
CVE-2026-44342
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing an attacker to trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth identity in deployments where session cookies could be sent on cross-site navigations. This issue is fixed in version 0.12.0-alpha.1.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/QuantumNous/new-apiGo | < 0.12.0-alpha.1 | 0.12.0-alpha.1 |
Affected products
1- Range: <0.12.0-alpha.1
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-26v7-h57m-gh9mghsaADVISORY
- github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0eghsax_refsource_MISCWEB
- github.com/QuantumNous/new-api/releases/tag/v0.12.0-alpha.1mitrex_refsource_MISC
- github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9mghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.