Junglewise Threat Intelligence

CVE-2026-9306: QuantumNous new-api authorization bypass in Midjourney Image Relay Endpoint

CVE-2026-9306 · Severity: low · CVSS 3.7 · Published 2026-05-23

Technologies: QuantumNous New API. Vendors: QuantumNous.

Executive brief

A security vulnerability exists in QuantumNous new-api, a tool used for managing and relaying AI service requests. An unauthenticated attacker can exploit a flaw in the Midjourney image relay component to view images generated by other users. This could lead to the unauthorized disclosure of private user content and intellectual property.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Midjourney Image Relay Endpoint of QuantumNous new-api up to version 0.12.1. The root cause is twofold: first, the route 'GET /mj/image/:id' in 'router/relay-router.go' is registered before authentication middleware is applied; second, the 'GetByOnlyMJId' function in 'model/midjourney.go' retrieves tasks based solely on the 'mj_id' without verifying user ownership. A remote, unauthenticated attacker can exploit this by guessing or obtaining a valid 'mj_id' to bypass authorization and stream another user's generated images directly from the server. While the attack is remote, it is classified as high complexity due to the requirement of identifying specific task IDs.

Affected products

  • QuantumNous new-api up to 0.12.1

Timeline

  • 2026-04-06: disclosed: Initial discovery and Gist publication by researcher YLChen-007.
  • 2026-05-23: advisory: CVE-2026-9306 published.

References

Related threats