Vulnerabilidades em QuantumNous

18 resultados
Análise Vexday

QuantumNous apresenta 12 vulnerabilidades registradas, com metade delas (6) publicadas nos últimos 90 dias, indicando atividade recente de descoberta. Nenhuma das vulnerabilidades está sendo explorada ativamente no campo (KEV zero) e não há críticas de severidade máxima, o que reduz o risco imediato. A fraqueza predominante é CWE-918 (Server-Side Request Forgery), típica de controles de validação inadequados em requisições, que merece atenção em revisões de código mas não constitui ameaça crítica neste contexto.

CVE-2026-41432HIGHNew API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota FraudEPSS 0.8%CVE-2026-71479CRITICALNew API: Integer overflow in quota billing yields negative charges (self-crediting)EPSS 0.6%CVE-2026-25591HIGHNew API has an SQL LIKE Wildcard Injection DoS via Token SearchEPSS 0.6%CVE-2026-64868HIGHNew API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body loggingEPSS 0.6%CVE-2026-64859CRITICALNew API: User List API Leaks Root User Access Token Leading to Privilege EscalationEPSS 0.6%CVE-2026-64866MEDIUMNew API: Admin can reset passkeys for same-level or higher-privileged usersEPSS 0.5%CVE-2026-9306MEDIUMQuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorizationEPSS 0.5%CVE-2026-32879MEDIUMNew API has passkey-based secure step-up verification bypass for root-only channel secret disclosureEPSS 0.5%CVE-2026-33655HIGHNew API: SSRF Protection Bypass via Unresolved Hostname in Notification URLsEPSS 0.4%CVE-2026-82909MEDIUMQuantumNous new-api Revoked API Token token session expirationEPSS 0.4%CVE-2026-30886MEDIUMNew API: IDOR in VideoProxy allows cross-user video content access via missing ownership checkEPSS 0.4%CVE-2026-9305MEDIUMQuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injectionEPSS 0.3%CVE-2026-42339HIGHNew API: SSRF Filter Bypass via 0.0.0.0EPSS 0.3%CVE-2026-64865MEDIUMNew API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypassEPSS 0.3%CVE-2025-62155HIGHQuantumNous New API Has SSRF BypassEPSS 0.3%CVE-2026-25802HIGHNew API has Potential XSS in its MarkdownRenderer componentEPSS 0.3%CVE-2025-59146HIGHNew API has Authenticated Server-Side Request Forgery (SSRF) issueEPSS 0.2%CVE-2026-44342MEDIUMNew API CSRF in email and WeChat account binding endpointsEPSS 0.2%