#2425·one-api

已验证: 管理员可以泄露根权限令牌并升级到 Root

作者: yaowenxiao721创建于 2026年7月6日更新于 2026年9月15日
标签bug

Summary

An authenticated admin can retrieve the root user's reusable management access_token from the admin-only user listing/search APIs and then use that token in the Authorization header to access Root-only endpoints. This creates a practical admin -> root privilege-escalation chain and results in full compromise of Root-only configuration APIs.

内容来源: songquanpeng/one-api