Skip to content
one-apiGHSA-7v3v-cp44-vc8m

songquanpeng one-api has an issue that results in business logic errors

Low3.1CVE-2026-11465 · Published Jun 8, 2026 · updated Aug 18, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/songquanpeng/one-api
Go
>= 0.1.6-alpha, <= 0.6.11-preview.7No fix yet
Details and references

A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
CVE-2026-11465, GO-2026-6126

More one-api advisories

All
DateAdvisory
Apr 192025one-api Cross-site Scripting vulnerability
CVE-2025-3801Medium2.4no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.