CVE-2026-25802Disclosure(newapi / new_api)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch newapi new_api systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version 0.10.8-alpha.9 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • new_api

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-24); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
new_api

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2702-2803-01
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure3Patch1
2026-02-271
Disclosure1
2026-02-281
General1
2026-03-011
General1
Full discourse7 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25802 Cross-Site Scripting Vulnerability in New API LLM Gateway Before 0.10.8-alpha.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25802

    Post summary

    A new XSS vulnerability (CVE-2026-25802) was disclosed in the New API LLM Gateway before version 0.10.8-alpha.9, with no PoC, exploit, or patch details provided.

    0001057
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25802 (CVSS:7.6, HIGH) is Analyzed. New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio..https://nvd.nist.gov/vuln/detail/CVE-2026-25802 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly references CVE-2026-25802, noting its CVSS score and that it involves a new LLM gateway API, but provides no further details or actionable information.

    0000031
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25802 (CVSS:7.6, HIGH) is Analyzed. New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio..https://nvd.nist.gov/vuln/detail/CVE-2026-25802 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet merely announces CVE-2026-25802 with its CVSS score and high severity, without providing evidence of exploits, PoC, active attacks, patches, or false‑positive claims.

    0000024
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25802 (CVSS:7.6, HIGH) is Analyzed. New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio..https://nvd.nist.gov/vuln/detail/CVE-2026-25802 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑25802, noting a high CVSS score of 7.6 and that it targets a new LLM gateway/AI asset management system, but provides no PoC, exploit code, or patch information.

    0000033
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25802 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation… https://www.cve.org/CVERecord?id=CVE-2026-25802

    Post summary

    A new CVE (CVE-2026-25802) affecting an LLM gateway AI asset management system is disclosed, noting a potential unsafe operation before version 0.10.8-alpha.9.

    00000333
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH-severity XSS in QuantumNous new-api (&lt;0.10.8-alpha.9) lets attackers inject scripts via MarkdownRenderer. Upgrade now to protect AI workflows! 🔒 https://radar.offseq.com/threat/cve-2026-25802-cwe-79-improper-neutralization-of-i-48d25c61 #OffSeq #XSS #AIsecurity https://t.co/yDm0anUfZR

    Post summary

    The tweet alerts to a high‑severity XSS vulnerability (CVE‑2026‑25802) in QuantumNous new‑api and urges users to upgrade to mitigate the risk.

    0000040
    269 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25802: Prompt Injection to Stored XSS: Unpacking CVE-2026-25802 in new-api A critical Cross-Site Scripting (XSS) vulnerability was discovered in the 'new-api' LLM gateway, specifically within its playground component. The flaw allows attacker... https://cvereports.com/reports/CVE-2026-25802

    Post summary

    The report announces a critical stored XSS vulnerability in the new‑api LLM gateway’s playground component, detailing the prompt injection flaw but providing no PoC, exploit, patch, or evidence of active exploitation.

    0000051
    31 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appnewapinew_api---
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--

Explore more