THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6x2c-phff-wx57 (critical) — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

[GHSA] GHSA-6x2c-phff-wx57 (critical) — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

highgithub_advisoriesPublished 2026-08-17

GHSA-6x2c-phff-wx57 Severity: critical CVE: CVE-2026-64859

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

## Vulnerability Information

- **Product**: new-api - **Affected versions**: versions before `v1.0.0-rc.7` that serialize `User.AccessToken` as `access_token`; the issue was confirmed in `v0.12.14` - **Patched version**: `v1.0.0-rc.7` - **Fixed commit**:

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6x2c-phff-wx57