Improper URL Validation in NextChat by ChatGPTNextWeb
CVE-2026-82639
8.7HIGH
What is CVE-2026-82639?
Versions 2.15.8 to 2.16.1 of NextChat contain an improper URL validation vulnerability in the proxy endpoint. This flaw allows attackers to exploit substring matching for the x-base-url header, which fails to accurately verify hostnames. Consequently, any URL that includes 'api.openai.com' can bypass validation, giving unauthorized access to the server's OpenAI API key, thereby exposing sensitive credentials through the Authorization header.
Affected Version(s)
NextChat 2.15.8 <= 2.16.1
