New API Passkey-Based Secure Verification Bypass Vulnerability

Vulnerability

A logic flaw has been identified in the secure verification process of New API, a large language model gateway and AI asset management system, starting from version 0.10.0. This vulnerability allows an authenticated user with a registered passkey to bypass the WebAuthn assertion requirement for secure verification. As a result, the user can complete the verification process without performing the necessary passkey challenge, potentially leading to unauthorized access to privileged actions that require secure verification.

Impact

Exploitation of this vulnerability bypasses the intended step-up verification for privileged actions, allowing access to sensitive endpoints without proper authentication. In the upstream project, this issue affects actions protected by SecureVerificationRequired(), specifically the root-only POST /api/channel/:id/key endpoint, which discloses stored channel secrets.

Remediation

Until a patched release is available, it is advised not to use passkeys as the step-up method for privileged secure-verification actions. Instead, require TOTP or two-factor authentication for these actions where operationally possible, or temporarily restrict access to endpoints protected by secure verification.

Added: Mar 23, 2026, 8:22 PM
Updated: Mar 23, 2026, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.