Affected by GO-2025-4154
and 4 other vulnerabilities
GO-2025-4154: new-api is vulnerable to SSRF Bypass in one-api
GO-2026-4531: New API has an SQL LIKE Wildcard Injection DoS via Token Search in github.com/QuantumNous/new-api
GO-2026-4532: New API has Potential XSS in its MarkdownRenderer component in github.com/QuantumNous/new-api
GO-2026-4813: New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api
GO-2026-4814: New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api
package
Version:
v0.10.4
Opens a new window with list of versions in this module.
Published: Dec 26, 2025
License:
UNKNOWN
not legal advice
Opens a new window with license information.
Imports: 61
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation not displayed due to license restrictions.
See our license policy.
Click to show internal directories.
Click to hide internal directories.