AI Asset Management System Vulnerability in New API by QuantumNous
CVE-2026-64865
6MEDIUM
What is CVE-2026-64865?
A race condition vulnerability exists in the New API's user management component that allows authenticated users to exploit the system when making repeated updates. By sending multiple PUT requests to the /api/user/self endpoint before version 1.0.0-rc.16, users could interfere with the quota deduction process, resulting in inflated cached quotas. This flaw arises due to concurrent write operations in the user management logic, thereby compromising the integrity of user quota management. The issue has been addressed in version 1.0.0-rc.16.
Affected Version(s)
new-api < 1.0.0-rc.16
