Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgrh-9fc9-55f9

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.9
CVSS3: 3.7

Описание

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 21%
0.00291
Низкий

2.9 Low

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 3.7
nvd
2 месяца назад

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 21%
0.00291
Низкий

2.9 Low

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-285