---
id: CVE-2026-85701
title: >-
  A vulnerability has been found in ramon-victor freegpt-webui up to
  098db3dfeb41555c2ca9269df0f13e10ec1c35dc
summary: >-
  A vulnerability has been found in ramon-victor freegpt-webui up to
  098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function
  ChatCompletion.create of the file g4f/__init__.py of the component
  Authentication Check. Such ma…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-287
  - CWE-306
vendor: ramon-victor
product: freegpt-webui
affected:
  - freegpt-webui 098db3dfeb41555c2ca9269df0f13e10ec1c35dc
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T18:21:13.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85701'
references:
  - url: 'https://gist.github.com/Galaxync/4e91898128de8fffbaf893fb1f9d4272'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-85701'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895266'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398799'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398799/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T17:53:40.035839Z'
epss: 0.00631
epssPercentile: 0.4799
ingestedAt: '2026-09-08T15:33:26.964Z'
---

## Overview

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
