Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects New API, an LLM gateway and AI asset management system. It could allow unauthorized manipulation of financial transactions, potentially leading to financial loss by converting charges into credits. The primary concern is confirming relevance and exposure to this system.
- Allows manipulation of financial transactions.
- Understand for potential financial implications.
- Confirm relevance and system exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending specially crafted requests to the New API, which acts as an LLM gateway. These requests would manipulate image, video, token, and audio duration parameters. If successful, the overflow in the conversion process could allow a user with a positive balance or active subscription to convert charges into credits, potentially leading to the draining of funds.
- No authentication required.
- Malicious input to quantity parameters.
- Financial fraud and fund draining.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, user-controlled quantities for image, video, tokens, and audio duration, along with billing expressions, could be manipulated through integer overflows. This could allow accounts with positive balances or active subscriptions to convert negative charges into account credit, potentially affecting upstream funds.
- Financial assets and billing data at risk.
- Negative charges converted to credit.
- Upstream funds may be drained.
Operational Fix
Recommended remediation, mitigation, and detection steps
The New API LLM gateway and AI asset management system is likely managed by platform or application teams responsible for AI services. The first action should be to identify all instances of this system, confirm their exposure and business criticality, and then determine the accountable owner to plan remediation.
- Platform or application teams should own this.
- Verify all system instances and exposure.
- Plan remediation based on risk and criticality.