Insecure API Access in New API Gateway by QuantumNous
CVE-2026-64859
9.1CRITICAL
What is CVE-2026-64859?
Prior to version 1.0.0-rc.7, the New API by QuantumNous exposes a significant vulnerability in its admin user list and user lookup APIs, specifically through the GET /api/user/ endpoint. This vulnerability allows an authenticated administrator to access the root user's bearer token due to improper serialization of User model objects, which inadvertently includes the User.AccessToken in the returned response. Such exposure can lead to unauthorized access to critical system configuration APIs. The issue has been addressed in the latest release, making it imperative for users to update to version 1.0.0-rc.7 or later to mitigate this risk.
Affected Version(s)
new-api < 1.0.0-rc.7
