CVE-2026-25591 | QuantumNous new-api up to 0.10.8-alpha.9 Token Search Endpoint /api/token/search keyword/token data query logic injection (GHSA-w6x6-9fp7-fqm4)
A vulnerability classified as problematic has been found in QuantumNous new-api up to 0.10.8-alpha.9. Impacted is an unknown function of the file /api/token/search of the component Token Search Endpoint. Performing a manipulation of the argument keyword/token results in improper neutralization of special elements in data query logic.
This vulnerability is identified as CVE-2026-25591. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.