PT-2025-47975 · Unknown · Llm Gateway

Published

2025-11-24

·

Updated

2026-05-18

·

CVE-2025-62155

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions New API versions prior to 0.9.6
Description New API is a large language model (LLM) gateway and artificial intelligence (AI) asset management system. A Server-Side Request Forgery (SSRF) condition existed in versions prior to 0.9.6. A previous security fix was susceptible to bypass through the use of HTTP 302 redirects. The initial fix only applied security restrictions to the first URL request, allowing attackers to leverage redirects to access internal network resources. The issue involves bypassing existing security measures to access the intranet.
Recommendations Update to New API version 0.9.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62155
GHSA-9F46-W24H-69W4
GO-2025-4154
SUSE-SU-2026:0037-1

Affected Products

Llm Gateway