CVE-2026-82639 – NextChat

CVSS 7.5 IMPORTANT Zero Day – Immediate Deployment

“A weak proxy validation check can expose the server’s OpenAI API key to an unauthenticated attacker.”

NextChat versions 2.15.8 through 2.16.1 contain a High-severity URL validation flaw in the proxy endpoint. CVE-2026-82639 allows an unauthenticated attacker to supply a malicious x-base-url value that passes substring validation and causes the server’s OpenAI API key to be forwarded to an attacker-controlled endpoint. The CVSS score is 7.5, which is High severity.

Public proof-of-concept material is available for the vulnerability. No confirmed patched release is listed in the supplied vulnerability record.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.