CVE-2026-64859: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, ret...
Added to the CISA Known Exploited Vulnerabilities catalog on 17 Aug 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 9.1.
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omi...
Required action: Review and patch if applicable to your AI infrastructure.