{"schema_version":"1.7.5","id":"GO-2026-4814","published":"2026-03-26T20:33:02Z","modified":"2026-03-26T21:03:43.627826Z","aliases":["CVE-2026-30886","GHSA-f35r-v9x5-r8mc"],"summary":"New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api","details":"New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api","affected":[{"package":{"name":"github.com/QuantumNous/new-api","ecosystem":"Go","purl":"pkg:golang/github.com/QuantumNous/new-api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.11.4-alpha.2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4814.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-f35r-v9x5-r8mc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30886"},{"type":"FIX","url":"https://github.com/QuantumNous/new-api/commit/50ec2bac6b341e651fc9ac4344e3bd2cdaeafdbd"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4814"}}