← Back

CVE-2026-32879

nvd nist
Published: Mar 23, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As of time of publication, no known patched versions are available. Until a patched release is applied, do not rely on passkey as the step-up method for privileged secure-verification actions; require TOTP/2FA for those actions where operationally possible; or temporarily restrict access to affected secure-verification-protected endpoints.

Affected (2)

Products: Newapi: New Api
1 product
New Api
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Newapi
From 0.10.0 to 0.11.9
Version 0.11.9 alpha1

References (1)

Source: security-advisories@github.com
MitigationVendor Advisory

Timeline

No history available yet.