CVE-2026-82639 – NextChat
CVSS 7.5
IMPORTANT
Zero Day – Immediate Deployment
“A weak proxy validation check can expose the server’s OpenAI API key to an unauthenticated attacker.”
NextChat versions 2.15.8 through 2.16.1 contain a High-severity URL validation flaw in the proxy endpoint. CVE-2026-82639 allows an unauthenticated attacker to supply a malicious x-base-url value that passes substring validation and causes the server’s OpenAI API key to be forwarded to an attacker-controlled endpoint. The CVSS score is 7.5, which is High severity.
Public proof-of-concept material is available for the vulnerability. No confirmed patched release is listed in the supplied vulnerability record.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-20
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.