Business Logic Flaw in songquanpeng one-api Redemption Code Top-Up Endpoint
CVE-2026-11465
Key Information:
- Vendor
Songquanpeng
- Status
- Vendor
- CVE Published:
- 7 June 2026
Badges
What is CVE-2026-11465?
A business logic flaw has been identified in the songquanpeng one-api, specifically within the Redeem function in the redemption.go file, impacting versions up to 0.6.11-preview.7. This vulnerability may allow attackers to manipulate redemption processes, potentially leading to unauthorized access or operation. Remote exploitation is possible, but it requires a sophisticated approach, making it challenging for attackers. A patch is currently pending acceptance to rectify this issue.
Affected Version(s)
one-api 0.6.11-preview.0
one-api 0.6.11-preview.1
one-api 0.6.11-preview.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
