CVE-2025-59146
New API has Authenticated Server-Side Request Forgery (SSRF) issue
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature within the application allows authenticated users to submit a URL for the server to process its content. The application fails to properly validate this user-supplied URL before making a server-side request. This vulnerability is not limited to image URLs and can be triggered with any link provided to the vulnerable endpoint. Since user registration is often enabled by default, any registered user can exploit this. By crafting a malicious URL, an attacker can coerce the server to send requests to arbitrary internal or external services. The vulnerability has been patched in version 0.9.0.5. The patch introduces a comprehensive, user-configurable SSRF protection module, which is enabled by default to protect server security. This new feature provides administrators with granular control over outbound requests made by the server. For users who cannot upgrade immediately, some temporary mitigation options are available. Enable new-api image processing worker (new-api-worker) and/or configure egress firewall rules.
INFO
Published Date :
Oct. 9, 2025, 7:15 p.m.
Last Modified :
Oct. 8, 2026, 1:10 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Upgrade to version 0.9.0.5 or later.
- Enable new-api image processing worker.
- Configure egress firewall rules.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-59146.
| URL | Resource |
|---|---|
| https://github.com/QuantumNous/new-api/commit/ef634160986c6f6b087cbfe131074fda862928af | |
| https://github.com/QuantumNous/new-api/security/advisories/GHSA-xxv6-m6fx-vfhh |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-59146 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-59146
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-59146 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2025-59146 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Oct. 08, 2026
Action Type Old Value New Value Added Translation Title: new-api de QuantumNous, Description: Nueva API es una pasarela de modelo de lenguaje grande (LLM) y un sistema de gestión de activos de inteligencia artificial (IA). Existe una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) autenticada en versiones anteriores a la 0.9.0.5. Una característica dentro de la aplicación permite a los usuarios autenticados enviar una URL para que el servidor procese su contenido. La aplicación no valida correctamente esta URL proporcionada por el usuario antes de realizar una petición del lado del servidor. Esta vulnerabilidad no se limita a las URL de imágenes y puede ser activada con cualquier enlace proporcionado al endpoint vulnerable. Dado que el registro de usuarios suele estar habilitado por defecto, cualquier usuario registrado puede explotar esto. Al elaborar una URL maliciosa, un atacante puede obligar al servidor a enviar peticiones a servicios internos o externos arbitrarios. La vulnerabilidad ha sido parcheada en la versión 0.9.0.5. El parche introduce un módulo de protección SSRF completo y configurable por el usuario, que está habilitado por defecto para proteger la seguridad del servidor. Esta nueva característica proporciona a los administradores un control granular sobre las peticiones salientes realizadas por el servidor. Para los usuarios que no pueden actualizar inmediatamente, algunas opciones de mitigación temporal están disponibles. Habilitar el trabajador de procesamiento de imágenes de new-api (new-api-worker) y/o configurar reglas de cortafuegos de egreso. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'QuantumNous', 'product': 'new-api', 'versions': [{'status': 'affected', 'version': '< 0.9.0.5'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2025-59146', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-10-09T19:07:35.742908Z'} -
New CVE Received by [email protected]
Oct. 09, 2025
Action Type Old Value New Value Added Description New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature within the application allows authenticated users to submit a URL for the server to process its content. The application fails to properly validate this user-supplied URL before making a server-side request. This vulnerability is not limited to image URLs and can be triggered with any link provided to the vulnerable endpoint. Since user registration is often enabled by default, any registered user can exploit this. By crafting a malicious URL, an attacker can coerce the server to send requests to arbitrary internal or external services. The vulnerability has been patched in version 0.9.0.5. The patch introduces a comprehensive, user-configurable SSRF protection module, which is enabled by default to protect server security. This new feature provides administrators with granular control over outbound requests made by the server. For users who cannot upgrade immediately, some temporary mitigation options are available. Enable new-api image processing worker (new-api-worker) and/or configure egress firewall rules. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N Added CWE CWE-918 Added Reference https://github.com/QuantumNous/new-api/commit/ef634160986c6f6b087cbfe131074fda862928af Added Reference https://github.com/QuantumNous/new-api/security/advisories/GHSA-xxv6-m6fx-vfhh