VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-82639

CVE-2026-82639: NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that

Published Aug 30, 2026 CVSS 8.7

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.

Affected AI Products

openai
Get the weekly digest. Every Monday: top AI security stories of the week. Free.