Executive brief
New API, a gateway for managing AI assets and large language models, contains a vulnerability in its payment processing system. An attacker can bypass the security checks for Stripe payments to falsely credit their account with unlimited usage quota without actually paying. This could lead to significant financial loss for the service provider and unauthorized consumption of expensive AI resources.
Technical details
The vulnerability arises from three primary flaws in the Stripe webhook implementation. First, the system defaults to an empty StripeWebhookSecret, which allows attackers to generate valid HMAC-SHA256 signatures using an empty key. Second, the handler fails to verify the 'payment_status' field, accepting 'unpaid' sessions as successful. Third, the Recharge function lacks PaymentMethod validation, allowing an attacker to create a pending order via any gateway (like Epay) and fulfill it using a forged Stripe webhook. Attackers can exploit this by retrieving a pending trade_no and sending a crafted POST request to the /api/stripe/webhook endpoint. The issue is patched in version 0.12.10 by requiring a non-empty secret and implementing strict payment method and status verification.
Affected products
- QuantumNous New API < v0.12.10
Timeline
- 2026-04-15: patched: Version 0.12.10 released
- 2026-04-22: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: CVE-2026-41432 published to NVD