CVE-2026-30886: New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check

Published Mar 23, 2026
·
Updated

Summary

The video proxy endpoint GET /v1/videos/:taskid/content is vulnerable to an Insecure Direct Object Reference (IDOR). Any authenticated user who knows another user's taskid can retrieve that user's generated video content because the handler queries tasks by taskid alone and does not verify ownership.

Affected Component

- Endpoint: GET /v1/videos/:taskid/content - Route middleware: TokenOrUserAuth() - Vulnerable handler: controller.VideoProxy

Details

VideoProxy fetches the task with:

go task, exists, err := model.GetByOnlyTaskId(taskID)

GetByOnlyTaskId performs a database lookup using only taskid:

go err = DB.Where("taskid = ?", taskId).First(&task).Error

The authenticated user's ID is available in request context, but VideoProxy does not use it. This allows any authenticated user to request /v1/videos/<foreigntaskid>/content and access another user's video if they know a valid task ID.

Other task-fetch paths already enforce ownership correctly via:

go model.GetByTaskId(userId, taskId)

Impact

An authenticated attacker who knows another user's taskid can:

- Download video content belonging to another user - Bypass tenant isolation for generated media assets - Cause the server to fetch upstream video content for a task the attacker does not own

For Gemini tasks, the proxy also uses task.PrivateData.Key when contacting the upstream provider. In addition, full upstream response headers are forwarded back to the requester.

Proof of Concept

bash curl -o stolenvideo.mp4 \ "https://<instance>/v1/videos/<victimtaskid>/content" \ -H "Authorization: Bearer sk-<attackertoken>"

Expected result:

- Response returns 200 OK - Response body contains the victim's video content

Recommended Fix

Replace the task lookup in VideoProxy with an ownership-checked query:

go userId := c.GetInt("id") task, exists, err := model.GetByTaskId(userId, taskID)

Other sources

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy endpoint (GET /v1/videos/:taskid/content) allows any authenticated user to access video content belonging to other users and causes the server to authenticate to upstream AI providers (Google Gemini, OpenAI) using credentials derived from tasks they do not own. The missing authorization check is a single function call — model.GetByOnlyTaskId(taskID) queries by taskid alone with no userid filter, while every other task-lookup in the codebase enforces ownership via model.GetByTaskId(userId, taskID). Version 0.11.4-alpha.2 contains a patch.

MITRE

Affected Software

4 affected componentsFixes available
New API<0.11.4-alpha.2
go/github.com/QuantumNous/new-api<0.11.4-alpha.2
0.11.4-alpha.2
Newapi New Api<0.11.4
Newapi New Api=0.11.4-alpha1

Event History

Mar 23, 2026
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·08:30 PM
Data Sourced
via GitHub·08:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-30886?

CVE-2026-30886 is classified as a moderate severity vulnerability due to the potential for unauthorized access to video content.

2

How do I fix CVE-2026-30886?

To fix CVE-2026-30886, upgrade the New API to version 0.11.4-alpha.2 or later, which implements the necessary ownership checks.

3

What kind of attack does CVE-2026-30886 enable?

CVE-2026-30886 enables an Insecure Direct Object Reference (IDOR) attack that allows an authenticated user to access another user's content if they know the task_id.

4

Which software versions are affected by CVE-2026-30886?

CVE-2026-30886 affects all versions of the New API prior to 0.11.4-alpha.2.

5

Who is impacted by CVE-2026-30886?

Any authenticated user of the New API is potentially impacted by CVE-2026-30886 if they can guess another user's task_id.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203