Cross-Site Scripting Vulnerability in New API by QuantumNous
CVE-2026-25802

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
24 February 2026

What is CVE-2026-25802?

The New API developed by QuantumNous contains a Cross-Site Scripting (XSS) vulnerability in the MarkdownRenderer.jsx component. This vulnerability allows attackers to inject malicious scripts into the output generated by the language model, leading to potential unauthorized actions or data theft. This issue affects versions prior to 0.10.8-alpha.9, where the flaw has been addressed in the subsequent release. It is crucial for users to upgrade their systems promptly to mitigate potential security risks.

Affected Version(s)

new-api < 0.10.8-alpha.9

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.