CVE-2026-30886 | QuantumNous new-api prior 0.11.4-alpha.2 Video Proxy Endpoint /v1/videos/ model.GetByOnlyTaskId task_id authorization (GHSA-f35r-v9x5-r8mc)
A vulnerability was found in QuantumNous new-api 0.8.5.2/0.9.0.5/0.9.6/0.10.8-alpha.9/0.10.8-alpha.10. It has been declared as problematic. This affects the function model.GetByOnlyTaskId of the file /v1/videos/ of the component Video Proxy Endpoint. The manipulation of the argument task_id results in authorization bypass.
This vulnerability is identified as CVE-2026-30886. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.