PT-2025-47975 · Unknown · Llm Gateway
Published
2025-11-24
·
Updated
2026-05-18
·
CVE-2025-62155
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
New API versions prior to 0.9.6
Description
New API is a large language model (LLM) gateway and artificial intelligence (AI) asset management system. A Server-Side Request Forgery (SSRF) condition existed in versions prior to 0.9.6. A previous security fix was susceptible to bypass through the use of HTTP 302 redirects. The initial fix only applied security restrictions to the first URL request, allowing attackers to leverage redirects to access internal network resources. The issue involves bypassing existing security measures to access the intranet.
Recommendations
Update to New API version 0.9.6.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Llm Gateway