CVE-2026-41432HIGH 8.2EPSS p17.0%
CVE-2026-41432CVE-2026-41432
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.
Scoring
| CVSS 3.1 | 8.2 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
| EPSS | 0.26% probability of exploitation · percentile 17.0% · 2026-06-19T12:03:05Z |
| Published | 2026-05-08 |
| Last modified | 2026-05-18 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Initialization of a Resource with an Insecure Defaultcwe-1188 | 0% | live |
| Weakness | Insufficient Verification of Data Authenticitycwe-345 | 0% | live |
| Weakness | Incorrect Authorizationcwe-863 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.