CyberRota Analysis
AI-GeneratedThe vulnerability allows low-privileged users with a positive balance or active subscription to exploit overflow conversions in the quota management system, potentially converting negative charges into account credit and draining upstream funds. Organizations utilizing the affected large language model gateway and AI asset management system should prioritize applying the patch in version 1.0.0-rc.18 to mitigate the risk of financial loss. Immediate action is crucial for any entity relying on this software for managing user accounts and billing.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.