Executive brief
New API, a management system for AI assets and language models, contains a security flaw that allows users to bypass internal network protections. By providing a specially crafted web address for notifications, an authenticated user can force the system to connect to internal servers or cloud metadata services that should be private. This could lead to the exposure of sensitive internal data or unauthorized access to other systems within the corporate network.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in QuantumNous New API prior to version 0.12.0-alpha.1. The root cause is a flaw in the URL validation logic where the 'ApplyIPFilterForDomain' setting was disabled by default. While the system checked domain allow/block lists, it did not resolve hostnames to their underlying IP addresses before making requests. This allows an authenticated attacker to configure notification URLs (such as Webhook, Bark, or Gotify) that point to internal IP addresses or cloud metadata services (e.g., 169.254.169.254). An attacker can exploit this to probe internal network services and potentially exfiltrate sensitive data. The issue is addressed in version 0.12.0-alpha.1 by enabling IP filtering for domains by default and hardening validation in the 'VideoProxy' and 'RelayMidjourneyImage' endpoints.
Affected products
- QuantumNous new-api < 0.12.0-alpha.1
Timeline
- 2026-03-31: patched: Fix committed and version 0.12.0-alpha.1 released.
- 2026-07-03: advisory: GitHub Security Advisory GHSA-6qcr-qxgr-m7fv published.
- 2026-07-09: disclosed: CVE-2026-33655 published to NVD.