HIGHVulnerability

CVE-2026-82639

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.

Properties

severity
HIGH
score
7.5
epss_score
0.00298
cve_id
CVE-2026-82639
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-30T14:17:03.750
last_modified
2026-09-10T15:53:23.707
epss_percentile
0.22412

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82639 — Ninja Signal Threat Intelligence | Ninja Signal