CVE-2026-41432: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows a...
Added to the CISA Known Exploited Vulnerabilities catalog on 08 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 7.1.
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account witho...
Required action: Review and patch if applicable to your AI infrastructure.