PT-2026-36625 · Nextchat · Nextchat
Yu_Bao
·
Published
2026-05-02
·
Updated
2026-05-02
·
CVE-2026-7643
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ChatGPTNextWeb NextChat versions prior to 2.16.2
Description
A flaw in the API Endpoint component within the Next.js file allows for a permissive cross-domain policy with untrusted domains. This issue enables a remote attacker to execute a manipulation that bypasses domain restrictions.
Recommendations
Update to version 2.16.2 or later.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextchat