CVE-2026-25802
HIGHQuantumNous new-api < 0.10.8-alpha.9 - Cross-Site Scripting in MarkdownRenderer.jsx
Title source: llmDescription
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version 0.10.8-alpha.9 fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/QuantumNous/new-api/security/advisories/GHSA-299v-8pq9-5gjq
Scores
CVSS v3
7.6
EPSS
0.0001
EPSS Percentile
2.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (3)
newapi/new_api
0.10.8 alpha1 (8 CPE variants)
newapi/new_api
< 0.10.8
QuantumNous/new-api
0 - 0.10.8-alpha.9Go
Published
Feb 24, 2026
Tracked Since
Feb 24, 2026