PT-2026-83559 · Nextchat · Nextchat

·

CVE-2026-82639

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NextChat versions 2.15.8 through 2.16.1
Description Improper URL validation in the proxy endpoint allows attackers to obtain the server's OpenAI API key. The system validates the x-base-url header using substring matching rather than hostname parsing. Consequently, any URL containing the string 'api.openai.com' can bypass validation, causing the server to send its credentials within the Authorization header to an attacker-controlled destination.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82639

Affected Products

Nextchat