ChatGPTNextWeb has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.4 (high).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
ChatGPTNextWeb vulnerabilities
CVEs affecting ChatGPTNextWeb, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-105238High· 7.3A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes…
▾ TwilightChatGPTNextWeb · NextChatvia NVD
CVE-2026-82639High· 7.5PoCNextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching …
▾ MidnightChatGPTNextWeb · NextChatEPSS 0.51%via NVD