THREAT OPS › Threat News › [GHSA] GHSA-6x2c-phff-wx57 (critical) — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
[GHSA] GHSA-6x2c-phff-wx57 (critical) — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
GHSA-6x2c-phff-wx57 Severity: critical CVE: CVE-2026-64859
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
## Vulnerability Information
- **Product**: new-api - **Affected versions**: versions before `v1.0.0-rc.7` that serialize `User.AccessToken` as `access_token`; the issue was confirmed in `v0.12.14` - **Patched version**: `v1.0.0-rc.7` - **Fixed commit**:
MITRE ATT&CK techniques
Indicators of compromise
- 0936e2504655a5cbf7bc3c388f6d3e2bb24916d3sha1
- CVE-2026-64859cve
Original source: https://github.com/advisories/GHSA-6x2c-phff-wx57