CVE-2026-82639: NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that
Summary
NextChat versions 2.15.8 through 2.16.1 have a security flaw in their proxy endpoint (a server component that forwards requests) where URL validation uses simple text matching instead of proper hostname parsing. This allows attackers to craft malicious URLs containing the text 'api.openai.com' to trick the server into sending its OpenAI API key (a secret credential for accessing OpenAI's services) to them.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
network
low
none
none
August 30, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82639
First tracked: August 30, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%