VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-41432

CVE-2026-41432: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio

Published May 8, 2026 CVSS 7.1

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.

Affected AI Products

llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.