Affected by GO-2025-4154
and 2 other vulnerabilities
GO-2025-4154 : new-api is vulnerable to SSRF Bypass in one-api
GO-2026-4813 : New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api
GO-2026-5652 : QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api
Discover Packages
github.com/QuantumNous/new-api
plugins
package
Version:
v1.0.0-rc.36
Opens a new window with list of versions in this module.
Published: Sep 8, 2026
License: AGPL-3.0
Opens a new window with license information.
Imports: 5
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
Documentation
¶
Icon returns the embedded sidecar logo for a factory plugin, if the plugin
directory ships an icon.svg or icon.png next to plugin.js.
IconDataURI returns the embedded factory logo in the same data URI form the
task_plugins.icon column stores, so factory and override logos share one
read path.
Source returns the embedded factory source for a task plugin key.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.