GHSA-5353-f8fq-65vc

Suggest an improvement
Source
https://github.com/advisories/GHSA-5353-f8fq-65vc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-5353-f8fq-65vc/GHSA-5353-f8fq-65vc.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-5353-f8fq-65vc
Aliases
Published
2026-03-23T19:56:00Z
Modified
2026-03-30T14:18:40Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure
Details

Summary

A logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion.

Affected versions

= v0.10.0

Description

The POST /api/verify endpoint supports multiple secure verification methods, including passkeys. When the request body contains {"method":"passkey"}, the server only checks whether the authenticated account has a passkey record on file and then marks the secure verification session as complete. It does not verify that the requester successfully completed a WebAuthn assertion.

As a result, an authenticated user who already has a valid session and a registered passkey can satisfy the secure verification requirement without performing the intended passkey challenge/response flow.

Impact

In the upstream project, this issue affects actions protected by SecureVerificationRequired(). At the time of publication, the confirmed upstream impact is the root-only POST /api/channel/:id/key endpoint, which returns stored channel secrets.

Successful exploitation requires:

  • an already authenticated session for the target account, and
  • a registered passkey on that account.

No full login bypass or cross-account privilege escalation has been confirmed in the upstream codebase. However, the issue defeats the intended step-up verification control for affected privileged actions.

Workarounds

Until a patched release is applied:

  • do not rely on passkey as the step-up method for privileged secure-verification actions;
  • require TOTP/2FA for those actions where operationally possible; or
  • temporarily restrict access to affected secure-verification-protected endpoints.
Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-23T19:56:00Z",
    "nvd_published_at":  "2026-03-23T20:16:27Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/QuantumNous/new-api

Package

Name
github.com/QuantumNous/new-api
View open source insights on deps.dev
Purl
pkg:golang/github.com/QuantumNous/new-api

Affected ranges

Type
SEMVER
Events
Introduced
0.10.0
Last Affected
0.11.9-alpha.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-5353-f8fq-65vc/GHSA-5353-f8fq-65vc.json"