Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-299v-8pq9-5gjq | New API has Potential XSS in its MarkdownRenderer component |
Sat, 28 Feb 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Newapi
Newapi new Api |
|
| CPEs | cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha1:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha2:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha3:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha4:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha5:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha6:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha7:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha8:*:*:*:*:*:* |
|
| Vendors & Products |
Newapi
Newapi new Api |
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Tue, 24 Feb 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version 0.10.8-alpha.9 fixes the issue. | |
| Title | New API has Potential XSS in its MarkdownRenderer component | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T14:58:43.459Z
Reserved: 2026-02-05T19:58:01.641Z
Link: CVE-2026-25802
Updated: 2026-02-26T14:58:34.000Z
Status : Analyzed
Published: 2026-02-24T01:16:14.927
Modified: 2026-02-25T20:17:51.200
Link: CVE-2026-25802
No data.
OpenCVE Enrichment
Updated: 2026-04-18T11:15:35Z
Github GHSA