{"id":"GHSA-26v7-h57m-gh9m","summary":"New API is vulnerable to CSRF through user email binding","details":"## Summary\n\nThe email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth identity.\n\nAffected endpoints included:\n\n- `GET /api/oauth/email/bind`\n- `GET /api/oauth/wechat/bind`\n\n## Impact\n\nA successful attack could change account binding state. For email binding, the attacker could bind an email address they control and then attempt follow-on account recovery flows. The default session cookie configuration uses `SameSite=Strict`, which mitigates common cross-site navigation attacks in modern browsers, so the issue is rated Medium.\n\n## Affected versions\n\nVersions before `v0.12.0-alpha.1` are affected.\n\n## Patches\n\nThis issue is fixed in `v0.12.0-alpha.1`. The fix changes email and WeChat binding routes from GET to POST and reads parameters from a JSON request body instead of query parameters. The same change set also normalizes password reset responses to avoid disclosing whether an email is registered.\n\n## Workarounds\n\nIf upgrading immediately is not possible, ensure session cookies are configured with strict SameSite behavior and block GET requests to `/api/oauth/email/bind` and `/api/oauth/wechat/bind` at the reverse proxy.\n\n## Resources\n\n- Fixed by commit `e099117c61391abdf888fb75e382a582e550bd0e`.\n- Relevant code paths: `router/api-router.go` and `controller/user.go`.","aliases":["CVE-2026-44342","GO-2026-5929"],"modified":"2026-07-21T19:53:47.155212347Z","published":"2026-07-07T13:01:49Z","database_specific":{"cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-07T13:01:49Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9m"},{"type":"WEB","url":"https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0e"},{"type":"PACKAGE","url":"https://github.com/QuantumNous/new-api"}],"affected":[{"package":{"name":"github.com/QuantumNous/new-api","ecosystem":"Go","purl":"pkg:golang/github.com/QuantumNous/new-api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.0-alpha.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-26v7-h57m-gh9m/GHSA-26v7-h57m-gh9m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}