GHSA-7v3v-cp44-vc8m

Suggest an improvement
Source
https://github.com/advisories/GHSA-7v3v-cp44-vc8m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7v3v-cp44-vc8m/GHSA-7v3v-cp44-vc8m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7v3v-cp44-vc8m
Aliases
Published
2026-06-08T00:30:25Z
Modified
2026-08-18T15:10:55Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
songquanpeng one-api has an issue that results in business logic errors
Details

A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-28T20:03:15Z",
    "nvd_published_at": "2026-06-07T23:16:42Z",
    "severity": "LOW"
}
References

Affected packages

Go / github.com/songquanpeng/one-api

Package

Name
github.com/songquanpeng/one-api
View open source insights on deps.dev
Purl
pkg:golang/github.com/songquanpeng/one-api

Affected ranges

Type
SEMVER
Events
Introduced
0.1.6-alpha
Last Affected
0.6.11-preview.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7v3v-cp44-vc8m/GHSA-7v3v-cp44-vc8m.json"