216.73.217.22

CVE-2026-25591

· Published 24/02/2026 01:16 · Modified 24/02/2026 14:13

Labels: CVE-2026-25591 2026-02-24CVE-2026-25591CWE-943[email protected]

Essential information

Published
24/02/2026 01:16
Modified
24/02/2026 14:13
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
unknown / ai asset management system cpe:2.3:a:unknown:ai_asset_management_system:<0.10.8-alpha.10:*:*:*:*:*:*:*

References