NextChat vulnerabilities
CVEs whose affected-version data names the NextChat package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-105238High· 7.3A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes…
▾ TwilightChatGPTNextWeb · NextChatvia NVD
CVE-2026-82639High· 7.5PoCNextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching …
▾ MidnightChatGPTNextWeb · NextChatEPSS 0.51%via NVD