Vendor
An authorization flaw in one-api allows authenticated users to bypass role checks and per-group restrictions by manipulating channel ID parameters to access unauthorized upstream provider keys.