Loading market data...
← Back to CVE feed

CVE-2026-82639

HIGH CVSS 7.5 View on NVD ↗

Description

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Aug 30, 2026 14:17 UTC Modified: Aug 30, 2026 14:17 UTC