CVE-2026-30886: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in...

Added to the CISA Known Exploited Vulnerabilities catalog on 23 Mar 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 6.5.

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy endpoint (`GET /v1/videos/:task_id/content`) allows any authenticated user to acces...

Required action: Review and patch if applicable to your AI infrastructure.