CVE-2026-44342: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email...

Added to the CISA Known Exploited Vulnerabilities catalog on 09 Jul 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 5.3.

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowi...

Required action: Review and patch if applicable to your AI infrastructure.