NextChat Vulnerability Exposes OpenAI API Keys
A critical improper URL validation vulnerability, identified as CVE-2026-82639, has been discovered in NextChat versions 2.15.8 through 2.16.1. This flaw in the proxy endpoint could allow attackers to bypass validation and potentially obtain the server's OpenAI API key from the Authorization header. Users are urged to update to patched versions to prevent unauthorized access and data compromise.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.