CVE-2026-32879 Details
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As of time of publication, no known patched versions are available. Until a patched release is applied, do not rely on passkey as the step-up method for privileged secure-verification actions; require TOTP/2FA for those actions where operationally possible; or temporarily restrict access to affected secure-verification-protected endpoints.
A logic flaw has been identified in the secure verification process of New API, a large language model gateway and AI asset management system, starting from version 0.10.0. This vulnerability allows an authenticated user with a registered passkey to bypass the WebAuthn assertion requirement for secure verification. As a result, the user can complete the verification process without performing the necessary passkey challenge, potentially leading to unauthorized access to privileged actions that require secure verification.
Until a patched release is available, it is advised not to use passkeys as the step-up method for privileged secure-verification actions. Instead, require TOTP or two-factor authentication for these actions where operationally possible, or temporarily restrict access to endpoints protected by secure verification.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/QuantumNous/new-api/security/advisories/GHSA-5353-f8fq-65vc | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| newapi new api | >= 0.10.0, < 0.11.9 0.11.9 alpha1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Mar 23, 2026 | New CVE Received | [email protected] |