Impact
A flaw in the Revoked API Token Handler of QuantumNous new‑api causes an attacker to force a session to expire by manipulating the /api/usage/token endpoint. The result is an unexpected loss of user authentication, disrupting normal service availability for legitimate users. The weakness is a session‑management issue (CWE‑613) that can be triggered remotely through crafted requests.
Affected Systems
QuantumNous new‑api component versions up to 1.0.0‑rc.15 are affected. Updating to 1.0.0‑rc.17 fixes the problem. No other software vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not in CISA KEV. The exploit is remote, relying on manipulation of authentication tokens via the exposed/unknown functionality at /api/usage/token. Because the flaw was publicly disclosed, it may be used by attackers seeking to disrupt user sessions.
OpenCVE Enrichment