{"data":{"id":"0d15f16c-f79e-4e50-9b26-e2d96a795839","title":"CVE-2026-82639: NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that","summary":"NextChat versions 2.15.8 through 2.16.1 have a security flaw in their proxy endpoint (a server component that forwards requests) where URL validation uses simple text matching instead of proper hostname parsing. This allows attackers to craft malicious URLs containing the text 'api.openai.com' to trick the server into sending its OpenAI API key (a secret credential for accessing OpenAI's services) to them.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82639","publishedAt":"2026-08-30T14:17:03.750Z","cveId":"CVE-2026-82639","cweIds":["CWE-20"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["NextChat","OpenAI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-30T14:17:03.750Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}