{"id":"CVE-2026-82639","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82639","summary":"NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The…","details":"NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.","published":"2026-08-30T14:17:03.750","modified":"2026-08-30T14:17:03.750","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ChatGPTNextWeb/NextChat"},{"type":"WEB","url":"https://github.com/ChatGPTNextWeb/NextChat/blob/v2.16.1/app/api/proxy.ts"},{"type":"WEB","url":"https://github.com/ChatGPTNextWeb/NextChat/issues/6814"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/nextchat-2.15.8-through-2.16.1-openai-api-key-disclosure"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-30T14:17:03.750"}}